<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.luccapirovano.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=209.87.206.13</id>
	<title>Lucca&#039;s Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.luccapirovano.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=209.87.206.13"/>
	<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php/Special:Contributions/209.87.206.13"/>
	<updated>2026-09-25T06:06:36Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.3</generator>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1207</id>
		<title>Anti-AI Scraper Tarpits</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1207"/>
		<updated>2026-04-02T23:30:35Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Some website hosts are having issues with scrapers hammering their sites. Below are tools and information that they are using to combat this:&lt;br /&gt;
&lt;br /&gt;
https://en.wikipedia.org/wiki/Tarpit_(networking)#Anti-AI_tarpits&lt;br /&gt;
&lt;br /&gt;
https://vercel.com/blog/the-rise-of-the-ai-crawler&lt;br /&gt;
&lt;br /&gt;
https://zadzmo.org/code/nepenthes/&lt;br /&gt;
&lt;br /&gt;
https://anubis.techaro.lol/&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1206</id>
		<title>Anti-AI Scraper Tarpits</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1206"/>
		<updated>2026-04-02T23:07:17Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Some website hosts are having issues with scrapers hammering their sites. Below are tools and information that they are using to combat this:&lt;br /&gt;
&lt;br /&gt;
https://en.wikipedia.org/wiki/Tarpit_(networking)#Anti-AI_tarpits&lt;br /&gt;
&lt;br /&gt;
https://zadzmo.org/code/nepenthes/&lt;br /&gt;
&lt;br /&gt;
https://anubis.techaro.lol/&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1205</id>
		<title>Anti-AI Scraper Tarpits</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Anti-AI_Scraper_Tarpits&amp;diff=1205"/>
		<updated>2026-04-02T23:07:11Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: Created page with &amp;quot;Some website hosts are having issues with scrapers hammering their sites. Below are tools and information that they are using to combat this:  https://en.wikipedia.org/wiki/Tarpit_(networking)#Anti-AI_tarpits https://zadzmo.org/code/nepenthes/ https://anubis.techaro.lol/&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Some website hosts are having issues with scrapers hammering their sites. Below are tools and information that they are using to combat this:&lt;br /&gt;
&lt;br /&gt;
https://en.wikipedia.org/wiki/Tarpit_(networking)#Anti-AI_tarpits&lt;br /&gt;
https://zadzmo.org/code/nepenthes/&lt;br /&gt;
https://anubis.techaro.lol/&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1204</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1204"/>
		<updated>2026-04-02T23:06:28Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(use ctrl+shift+t to change theme settings)&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf (pdf)] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf (pdf)] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] | [[Performing a SYN flood attack]] | [https://attack.mitre.org/matrices/enterprise/ Mitre Att&amp;amp;ck] | [https://en.wikipedia.org/wiki/Christmas_tree_packet Christmas Tree Packet]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networking/Cisco: | [[Cisco Commands]] | [[Cisco Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]] | [[Anti-AI Scraper Tarpits]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf (pdf)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] | [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis] | [https://en.wikipedia.org/wiki/Anna&#039;s_Archive Anna&#039;s Archive]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tech &amp;amp; Vulnerability News: | [https://lwn.net/ LWN.net] | [https://news.ycombinator.com/ Hacker News]&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1203</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1203"/>
		<updated>2026-04-02T22:59:30Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(use ctrl+shift+t to change theme settings)&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf (pdf)] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf (pdf)] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] | [[Performing a SYN flood attack]] | [https://attack.mitre.org/matrices/enterprise/ Mitre Att&amp;amp;ck] | [https://en.wikipedia.org/wiki/Christmas_tree_packet Christmas Tree Packet]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networking/Cisco: | [[Cisco Commands]] | [[Cisco Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]] | [https://en.wikipedia.org/wiki/Tarpit_(networking)#Anti-AI_tarpits Anti-Ai Scraper Tarpits]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf (pdf)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] | [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis] | [https://en.wikipedia.org/wiki/Anna&#039;s_Archive Anna&#039;s Archive]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tech &amp;amp; Vulnerability News: | [https://lwn.net/ LWN.net] | [https://news.ycombinator.com/ Hacker News]&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1202</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1202"/>
		<updated>2026-04-02T22:58:25Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(use ctrl+shift+t to change theme settings)&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf (pdf)] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf (pdf)] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] | [[Performing a SYN flood attack]] | [https://attack.mitre.org/matrices/enterprise/ Mitre Att&amp;amp;ck] | [https://en.wikipedia.org/wiki/Christmas_tree_packet Christmas Tree Packet]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networking/Cisco: | [[Cisco Commands]] | [[Cisco Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf (pdf)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] | [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis] | [https://en.wikipedia.org/wiki/Anna&#039;s_Archive Anna&#039;s Archive]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tech &amp;amp; Vulnerability News: | [https://lwn.net/ LWN.net] | [https://news.ycombinator.com/ Hacker News]&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Commands&amp;diff=1144</id>
		<title>Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Commands&amp;diff=1144"/>
		<updated>2026-03-19T23:08:38Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;This page includes both cmd and powershell commands, realistically, all of them should run from powershell anyway.&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;ipconfig&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ipconfig command is a command-line utility used to display and manage the IP address assigned to a machine. It provides information about the current TCP/IP network configuration, including the IP address, subnet mask, and default gateway for all adapters . In Windows, typing ipconfig without any parameters displays the computer&#039;s currently assigned IP, subnet mask, and default gateway addresses. Additional parameters can be used to perform various actions, such as releasing and renewing IP addresses, flushing the DNS cache, and displaying DNS information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the basic TCP/IP configuration for all adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /all&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the full TCP/IP configuration for all adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /release&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Releases the IP address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /renew&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Renews the IP address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /flushdns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Purges the DNS resolver cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /registerdns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Refreshes all DHCP leases and re-registers DNS names.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /displaydns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the contents of the DNS cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /showclassid&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /setclassid&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Sets the DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /allcompartments&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the full TCP/IP configuration for all adapters, including all compartments.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /release6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Releases the IPv6 address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /renew6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Renews the IPv6 address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /showclassid6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the IPv6 DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /setclassid6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Sets the IPv6 DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /flushdns6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Purges the IPv6 DNS resolver cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
USE THIS IF WINDOWS IS ACTING UP HELLA WEIRD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt; command is used to scan for corruption in the Windows image and repair any issues found. DISM stands for Deployment Image Servicing and Management, and it is a command-line tool used to service and prepare Windows images for deployment, recovery, and setup.&lt;br /&gt;
&lt;br /&gt;
When you run the &amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt; command, it performs the following tasks:&lt;br /&gt;
&lt;br /&gt;
Scans the Windows image for corruption and identifies any issues.&lt;br /&gt;
Verifies the integrity of the system file backups in the Component Store by comparing them against known good copies from the Windows Update servers.&lt;br /&gt;
Attempts to repair any corruption found in the Windows image by replacing the corrupted files with the known good copies.&lt;br /&gt;
&lt;br /&gt;
It&#039;s important to note that running this command requires administrative privileges, and it may take some time to complete, depending on the system and the extent of the corruption.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-open cmd in admin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-after running DISM, run this right after, if errors are found, it will fix it, reboot pc&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;SFC /scannow&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-after reboot, run CMD as admin and run again&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;SFC /scannow&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-Let&#039;s not forget the G.O.A.T., Use in Run to reset internet settings especially if you are having connecting MS app online or if Sonicwall Netextender breaks the connection&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;RunDll32.exe InetCpl.cpl,ResetIEtoDefaults&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
How to find mapped drives on cmd:&lt;br /&gt;
&lt;br /&gt;
Open the Run dialog box by pressing the Windows &amp;lt;code&amp;gt;key + R.&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Type &amp;quot;cmd&amp;quot; and press Enter to open the Command Prompt.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use&amp;lt;/code&amp;gt; and press Enter to see a list of all mapped network drives.&lt;br /&gt;
&lt;br /&gt;
Find the drive you want to reconnect and take note of its name.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use &amp;lt;drive letter&amp;gt;: /delete&amp;lt;/code&amp;gt; and press Enter to delete the mapping.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use &amp;lt;drive letter&amp;gt;: \server\share /persistent:yes&amp;lt;/code&amp;gt; and press Enter to&lt;br /&gt;
recreate the mapping with the &amp;quot;persistent&amp;quot; option, which should keep the mapping&lt;br /&gt;
alive even after a disconnect.&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Create a Local user with CMD and make it into Admin, IF The username has a period in between please use the quotations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;user.name&amp;quot; password /add&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
then&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net localgroup administrators &amp;quot;user.name&amp;quot; /add&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you need to remove Admin creds&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net localgroup administrators &amp;quot;user.name&amp;quot; /delete&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
if you need to delete the local account&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;user.name&amp;quot; /delete&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Disable builtin Administrator and Guest accounts:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;Administrator&amp;quot; /active:no&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;Guest&amp;quot; /active:no&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable hibernation file to resolve issues with shutdown and free up some disk space.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;powercfg.exe /Hibernate off&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Log off someone from a desktop session&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
List all sessions: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;query session&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logoff the corresponding session:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;logoff {number}&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix right click on Windows 11, doesn&#039;t need admin:&lt;br /&gt;
&lt;br /&gt;
 reg.exe add &amp;quot;HKCU\Software\Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32&amp;quot; /f /ve&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix alt key opening hamburger menu on ms edge [needs admin]:&lt;br /&gt;
&lt;br /&gt;
 reg add HKLM\SOFTWARE\Policies\Microsoft\Edge /v ConfigureKeyboardShortcuts /d {\&amp;quot;disabled\&amp;quot;:[\&amp;quot;focus_settings_and_more\&amp;quot;]}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable Widgets button on the taskbar.&lt;br /&gt;
 reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v TaskbarDa /t REG_DWORD /d 0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Check if the Password is Expired&lt;br /&gt;
&lt;br /&gt;
 Get-ADUser -identity INSERTclientUSERNAMEHERE -properties PasswordLastSet, PasswordExpired, PasswordNeverExpires | ft Name, PasswordLastSet, PasswordExpired, PasswordNeverExpires&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Force the DC to sync the password&lt;br /&gt;
&lt;br /&gt;
 start-adsyncsynccycle -policytype delta&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Join a domain&lt;br /&gt;
&lt;br /&gt;
 add-computer -domainname &amp;quot;YourDomainName&amp;quot;  -restart&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Getting New Teams to install when it refuses to [Needs Admin]&lt;br /&gt;
&lt;br /&gt;
 Add-ProvisionedAppPackage -Online -PackagePath &amp;quot;MSTeams-x64.msix&amp;quot; -SkipLicense&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
List Services and their running status&lt;br /&gt;
&lt;br /&gt;
 Get-Service&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set a service to autostart&lt;br /&gt;
&lt;br /&gt;
 Set-Service -Name {servicename} -StartupType &#039;Automatic&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Start/Stop a service&lt;br /&gt;
&lt;br /&gt;
 Start-Service {servicename}&lt;br /&gt;
 Stop-Service {servicename}&lt;br /&gt;
 Restart-Service {servicename}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install OpenSSH-Server&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remove all default gateways from a network adapter&lt;br /&gt;
&lt;br /&gt;
 Remove-NetRoute -InterfaceAlias &amp;quot;{get this name from Get-NetAdapter}&amp;quot; -DestinationPrefix 0.0.0.0/0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IP Address&lt;br /&gt;
&lt;br /&gt;
 Get-NetAdapter -Name &#039;{get this name from Get-NetAdapter}&#039; | New-NetIPAddress -IPAddress {newIP} -PrefixLength {subnet mask [cidr]}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Allow inbound Ipv4 Pings&lt;br /&gt;
 netsh advfirewall firewall add rule name=&amp;quot;ICMP Allow incoming V4 echo request&amp;quot; protocol=icmpv4:8,any dir=in action=allow&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Show all WiFi Passwords [CMD Only]&lt;br /&gt;
 for /f &amp;quot;skip=9 tokens=1,2 delims=:&amp;quot; %i in (&#039;netsh wlan show profiles&#039;) do @if &amp;quot;%j&amp;quot; NEQ &amp;quot;&amp;quot; (echo SSID: %j &amp;amp; netsh wlan show profiles %j key=clear | findstr &amp;quot;Key Content&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install server manager on a Non-Windows-Server OS&lt;br /&gt;
 Get-WindowsCapability -Name RSAT* -Online | Add-WindowsCapability -Online&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Force update Group Policy (apply group policy changes)&lt;br /&gt;
 gpupdate.exe /force&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Resize a VHD [Virtual Hard Disk]&lt;br /&gt;
 resize-vhd -path &amp;quot;f:\Shares\profiledisks&amp;quot; -Sizebytes 30GB&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Persistently map a drive&lt;br /&gt;
 net use /persistent:yes h: \\VBoxSvr\Win11\Documents &lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Switch to compact os mode to save space&lt;br /&gt;
 Compact.exe /CompactOS:always&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Migrate a folder from one drive to the other preserving permissions and logging everything to the D:\ drive&lt;br /&gt;
 robocopy &amp;quot;C:\users\awesome.guy&amp;quot; &amp;quot;D:\users\awesome.guy&amp;quot; /E /COPYALL /zb /r:10 /w:10 /tee /unilog+:&amp;quot;D:\robocopylog.txt&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Add a domain to the global dns search list&lt;br /&gt;
 Set-DnsClientGlobalSetting -SuffixSearchList @(&amp;quot;corp.mariocorp.com&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix windows update not showing in the settings page (some RMM&#039;s do this by design to handle patching themselves)&lt;br /&gt;
 reg delete &amp;quot;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer&amp;quot; /v SettingsPageVisibility /f&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable Wi-Fi searching. This allows for more stable wi-fi performance at the cost of being able to see networks that pop up in realtime.&lt;br /&gt;
 netsh wlan set autoconfig enabled=no interface=&amp;quot;Wi-Fi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Enable Wi-Fi searching. This reverts the above command.&lt;br /&gt;
 netsh wlan set autoconfig enabled=yes interface=&amp;quot;Wi-Fi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Vim One-liner (Powershell only) (SYSTEM WIDE, NEEDS ADMIN)&lt;br /&gt;
 mkdir vim-install; cd vim-install; $ProgressPreference = &#039;SilentlyContinue&#039;; Invoke-Webrequest -UseBasicParsing https://github.com/vim/vim-win32-installer/releases/download/v9.1.0/gvim_9.1.0_x86_signed.zip -o gvim.zip; Expand-Archive -Path gvim.zip -DestinationPath .; cp .\vim\vim91\vim.exe C:\windows\system32\vim.exe&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Vim One-liner (Powershell only) (user only)&lt;br /&gt;
 mkdir vim-install; cd vim-install; $ProgressPreference = &#039;SilentlyContinue&#039;; Invoke-Webrequest -UseBasicParsing https://github.com/vim/vim-win32-installer/releases/download/v9.1.0/gvim_9.1.0_x86_signed.zip -o gvim.zip; Expand-Archive -Path gvim.zip -DestinationPath .; cp .\vim\vim91\vim.exe %localappdata%\Microsoft\WindowsApps\vim.exe&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Git One-liner&lt;br /&gt;
 winget install --id Git.Git -e --source winget --scope user&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set Hostname&lt;br /&gt;
 Rename-Computer -NewName &amp;quot;YourNewHostname&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Run Firefox with the profile selector screen&lt;br /&gt;
 &amp;quot;C:\Program Files\Mozilla Firefox\firefox.exe&amp;quot; --ProfileManager&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Delete all drive mappings / remove all network drives&lt;br /&gt;
 net use * /delete&lt;br /&gt;
&lt;br /&gt;
Ping with timestamp (Powershell only)&lt;br /&gt;
 ping google.com -t | % { &amp;quot;$(Get-Date -Format &#039;yyyy-MM-dd HH:mm:ss&#039;) $_&amp;quot; }&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Infared_Reciever_w/_Alpine_on_the_Bulldozer_Datto&amp;diff=1143</id>
		<title>Infared Reciever w/ Alpine on the Bulldozer Datto</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Infared_Reciever_w/_Alpine_on_the_Bulldozer_Datto&amp;diff=1143"/>
		<updated>2026-03-18T18:54:49Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Had some issues with the bootloader after installing alpine originally, ended up using ventoy&#039;s &amp;quot;Local Boot&amp;quot; option to get into my alpine install and then manually installed grub using:&lt;br /&gt;
&amp;lt;code&amp;gt;grub-install&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Now we need to get wifi working: [https://wiki.alpinelinux.org/wiki/NetworkManager]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;vim /etc/apk/repositories&amp;lt;/code&amp;gt; and uncomment the community repo&lt;br /&gt;
&lt;br /&gt;
We&#039;ll be needing these packages:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;apk add networkmanager networkmanager-wifi wpa_supplicant networkmanager-tui networkmanager-cli&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networkmanager needs udev to work for wifi:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;setup-devd udev&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Getting infared working:&lt;br /&gt;
&lt;br /&gt;
Looks like alpine has some infared tools in a package called:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;v4l-utils&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ir_keytable&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ir-ctl -d /dev/lirc0 -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
running this gets me data when i click ir buttons on some remotes&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Figured out LIRC, on alpine the config is in &amp;lt;code&amp;gt;/usr/etc/lirc/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
first we need to install it:&lt;br /&gt;
 apk install lirc&lt;br /&gt;
&lt;br /&gt;
lirc_options.conf:&lt;br /&gt;
  # These are the default options to lircd, if installed as&lt;br /&gt;
  # /etc/lirc/lirc_options.conf. See the lircd(8) and lircmd(8)&lt;br /&gt;
  # manpages for info on the different options.&lt;br /&gt;
  #&lt;br /&gt;
  # Some tools including mode2 and irw uses values such as&lt;br /&gt;
  # driver, device, plugindir and loglevel as fallback values&lt;br /&gt;
  # in not defined elsewhere.&lt;br /&gt;
  [lircd]&lt;br /&gt;
  nodaemon        = True&lt;br /&gt;
  driver          = default&lt;br /&gt;
  device          = auto&lt;br /&gt;
  output          = /var/run/lirc/lircd&lt;br /&gt;
  pidfile         = /var/run/lirc/lircd.pid&lt;br /&gt;
  plugindir       = /usr/lib/lirc/plugins&lt;br /&gt;
  permission      = 666&lt;br /&gt;
  allow-simulate  = No&lt;br /&gt;
  repeat-max      = 600&lt;br /&gt;
  #effective-user =&lt;br /&gt;
  #listen         = [address:]port&lt;br /&gt;
  #connect        = host[:port]&lt;br /&gt;
  #loglevel       = 6&lt;br /&gt;
  #release        = true&lt;br /&gt;
  #release_suffix = _EVUP&lt;br /&gt;
  #logfile        = ...&lt;br /&gt;
  #driver-options = ...&lt;br /&gt;
  [lircmd]&lt;br /&gt;
  uinput          = False&lt;br /&gt;
  nodaemon        = False&lt;br /&gt;
  # [modinit]&lt;br /&gt;
  # code = /usr/sbin/modprobe lirc_serial&lt;br /&gt;
  # code1 = /usr/bin/setfacl -m g:lirc:rw /dev/uinput&lt;br /&gt;
  # code2 = ...&lt;br /&gt;
  # [lircd-uinput]&lt;br /&gt;
  # add-release-events = False&lt;br /&gt;
  # release-timeout    = 200&lt;br /&gt;
  # release-suffix     = _EVUP&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Make a folder called lircd.conf.d, place this file inside: https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/infared%20project/BN59-01175B.lircd.conf&lt;br /&gt;
&lt;br /&gt;
(you can get additional remote configs [https://lirc-remotes.sourceforge.net/remotes-table.html here])&lt;br /&gt;
&lt;br /&gt;
lirc will detect the file automatically when it is opened&lt;br /&gt;
&lt;br /&gt;
Now we need to run lirc daemon: &amp;lt;code&amp;gt;lircd&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
below is a script that will allow you to execute bash commands based on remote presses, taking advantage of &amp;lt;code&amp;gt;irw&amp;lt;/code&amp;gt;&#039;s output:&lt;br /&gt;
 #!/bin/bash&lt;br /&gt;
 irw |&lt;br /&gt;
 while &lt;br /&gt;
  read;&lt;br /&gt;
  do&lt;br /&gt;
   if echo &amp;quot;$REPLY&amp;quot; | fgrep &amp;quot;01 KEY_0&amp;quot;; then echo &amp;quot;this is button 0&amp;quot;; fi&lt;br /&gt;
   if echo &amp;quot;$REPLY&amp;quot; | fgrep &amp;quot;01 KEY_1&amp;quot;; then echo &amp;quot;this is button 1&amp;quot;; fi&lt;br /&gt;
   if echo &amp;quot;$REPLY&amp;quot; | fgrep &amp;quot;01 KEY_2&amp;quot;; then echo &amp;quot;this is button 2&amp;quot;; fi&lt;br /&gt;
   if echo &amp;quot;$REPLY&amp;quot; | fgrep &amp;quot;00 KEY_3&amp;quot;; then echo &amp;quot;this is button 3&amp;quot;; fi&lt;br /&gt;
  done&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Commands&amp;diff=1139</id>
		<title>Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Commands&amp;diff=1139"/>
		<updated>2026-02-26T17:42:55Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;This page includes both cmd and powershell commands, realistically, all of them should run from powershell anyway.&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;ipconfig&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The ipconfig command is a command-line utility used to display and manage the IP address assigned to a machine. It provides information about the current TCP/IP network configuration, including the IP address, subnet mask, and default gateway for all adapters . In Windows, typing ipconfig without any parameters displays the computer&#039;s currently assigned IP, subnet mask, and default gateway addresses. Additional parameters can be used to perform various actions, such as releasing and renewing IP addresses, flushing the DNS cache, and displaying DNS information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the basic TCP/IP configuration for all adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /all&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the full TCP/IP configuration for all adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /release&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Releases the IP address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /renew&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Renews the IP address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /flushdns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Purges the DNS resolver cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /registerdns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Refreshes all DHCP leases and re-registers DNS names.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /displaydns&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the contents of the DNS cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /showclassid&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /setclassid&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Sets the DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /allcompartments&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the full TCP/IP configuration for all adapters, including all compartments.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /release6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Releases the IPv6 address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /renew6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Renews the IPv6 address assigned to the computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /showclassid6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Displays the IPv6 DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /setclassid6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Sets the IPv6 DHCP class ID for network adapters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ipconfig /flushdns6&amp;lt;/code&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Purges the IPv6 DNS resolver cache.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
USE THIS IF WINDOWS IS ACTING UP HELLA WEIRD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt; command is used to scan for corruption in the Windows image and repair any issues found. DISM stands for Deployment Image Servicing and Management, and it is a command-line tool used to service and prepare Windows images for deployment, recovery, and setup.&lt;br /&gt;
&lt;br /&gt;
When you run the &amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt; command, it performs the following tasks:&lt;br /&gt;
&lt;br /&gt;
Scans the Windows image for corruption and identifies any issues.&lt;br /&gt;
Verifies the integrity of the system file backups in the Component Store by comparing them against known good copies from the Windows Update servers.&lt;br /&gt;
Attempts to repair any corruption found in the Windows image by replacing the corrupted files with the known good copies.&lt;br /&gt;
&lt;br /&gt;
It&#039;s important to note that running this command requires administrative privileges, and it may take some time to complete, depending on the system and the extent of the corruption.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-open cmd in admin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;DISM /Online /Cleanup-Image /RestoreHealth&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-after running DISM, run this right after, if errors are found, it will fix it, reboot pc&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;SFC /scannow&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-after reboot, run CMD as admin and run again&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;SFC /scannow&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-Let&#039;s not forget the G.O.A.T., Use in Run to reset internet settings especially if you are having connecting MS app online or if Sonicwall Netextender breaks the connection&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;RunDll32.exe InetCpl.cpl,ResetIEtoDefaults&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
How to find mapped drives on cmd:&lt;br /&gt;
&lt;br /&gt;
Open the Run dialog box by pressing the Windows &amp;lt;code&amp;gt;key + R.&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Type &amp;quot;cmd&amp;quot; and press Enter to open the Command Prompt.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use&amp;lt;/code&amp;gt; and press Enter to see a list of all mapped network drives.&lt;br /&gt;
&lt;br /&gt;
Find the drive you want to reconnect and take note of its name.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use &amp;lt;drive letter&amp;gt;: /delete&amp;lt;/code&amp;gt; and press Enter to delete the mapping.&lt;br /&gt;
&lt;br /&gt;
Type &amp;lt;code&amp;gt;net use &amp;lt;drive letter&amp;gt;: \server\share /persistent:yes&amp;lt;/code&amp;gt; and press Enter to&lt;br /&gt;
recreate the mapping with the &amp;quot;persistent&amp;quot; option, which should keep the mapping&lt;br /&gt;
alive even after a disconnect.&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Create a Local user with CMD and make it into Admin, IF The username has a period in between please use the quotations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;user.name&amp;quot; password /add&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
then&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net localgroup administrators &amp;quot;user.name&amp;quot; /add&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you need to remove Admin creds&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net localgroup administrators &amp;quot;user.name&amp;quot; /delete&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
if you need to delete the local account&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;user.name&amp;quot; /delete&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Disable builtin Administrator and Guest accounts:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;Administrator&amp;quot; /active:no&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;net user &amp;quot;Guest&amp;quot; /active:no&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable hibernation file to resolve issues with shutdown and free up some disk space.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;powercfg.exe /Hibernate off&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Log off someone from a desktop session&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
List all sessions: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;query session&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logoff the corresponding session:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;logoff {number}&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix right click on Windows 11, doesn&#039;t need admin:&lt;br /&gt;
&lt;br /&gt;
 reg.exe add &amp;quot;HKCU\Software\Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32&amp;quot; /f /ve&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix alt key opening hamburger menu on ms edge [needs admin]:&lt;br /&gt;
&lt;br /&gt;
 reg add HKLM\SOFTWARE\Policies\Microsoft\Edge /v ConfigureKeyboardShortcuts /d {\&amp;quot;disabled\&amp;quot;:[\&amp;quot;focus_settings_and_more\&amp;quot;]}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable Widgets button on the taskbar.&lt;br /&gt;
 reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v TaskbarDa /t REG_DWORD /d 0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Check if the Password is Expired&lt;br /&gt;
&lt;br /&gt;
 Get-ADUser -identity INSERTclientUSERNAMEHERE -properties PasswordLastSet, PasswordExpired, PasswordNeverExpires | ft Name, PasswordLastSet, PasswordExpired, PasswordNeverExpires&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Force the DC to sync the password&lt;br /&gt;
&lt;br /&gt;
 start-adsyncsynccycle -policytype delta&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Join a domain&lt;br /&gt;
&lt;br /&gt;
 add-computer -domainname &amp;quot;YourDomainName&amp;quot;  -restart&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Getting New Teams to install when it refuses to [Needs Admin]&lt;br /&gt;
&lt;br /&gt;
 Add-ProvisionedAppPackage -Online -PackagePath &amp;quot;MSTeams-x64.msix&amp;quot; -SkipLicense&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
List Services and their running status&lt;br /&gt;
&lt;br /&gt;
 Get-Service&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set a service to autostart&lt;br /&gt;
&lt;br /&gt;
 Set-Service -Name {servicename} -StartupType &#039;Automatic&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Start/Stop a service&lt;br /&gt;
&lt;br /&gt;
 Start-Service {servicename}&lt;br /&gt;
 Stop-Service {servicename}&lt;br /&gt;
 Restart-Service {servicename}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install OpenSSH-Server&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remove all default gateways from a network adapter&lt;br /&gt;
&lt;br /&gt;
 Remove-NetRoute -InterfaceAlias &amp;quot;{get this name from Get-NetAdapter}&amp;quot; -DestinationPrefix 0.0.0.0/0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IP Address&lt;br /&gt;
&lt;br /&gt;
 Get-NetAdapter -Name &#039;{get this name from Get-NetAdapter}&#039; | New-NetIPAddress -IPAddress {newIP} -PrefixLength {subnet mask [cidr]}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Allow inbound Ipv4 Pings&lt;br /&gt;
 netsh advfirewall firewall add rule name=&amp;quot;ICMP Allow incoming V4 echo request&amp;quot; protocol=icmpv4:8,any dir=in action=allow&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Show all WiFi Passwords [CMD Only]&lt;br /&gt;
 for /f &amp;quot;skip=9 tokens=1,2 delims=:&amp;quot; %i in (&#039;netsh wlan show profiles&#039;) do @if &amp;quot;%j&amp;quot; NEQ &amp;quot;&amp;quot; (echo SSID: %j &amp;amp; netsh wlan show profiles %j key=clear | findstr &amp;quot;Key Content&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install server manager on a Non-Windows-Server OS&lt;br /&gt;
 Get-WindowsCapability -Name RSAT* -Online | Add-WindowsCapability -Online&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Force update Group Policy (apply group policy changes)&lt;br /&gt;
 gpupdate.exe /force&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Resize a VHD [Virtual Hard Disk]&lt;br /&gt;
 resize-vhd -path &amp;quot;f:\Shares\profiledisks&amp;quot; -Sizebytes 30GB&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Persistently map a drive&lt;br /&gt;
 net use /persistent:yes h: \\VBoxSvr\Win11\Documents &lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Switch to compact os mode to save space&lt;br /&gt;
 Compact.exe /CompactOS:always&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Migrate a folder from one drive to the other preserving permissions and logging everything to the D:\ drive&lt;br /&gt;
 robocopy &amp;quot;C:\users\awesome.guy&amp;quot; &amp;quot;D:\users\awesome.guy&amp;quot; /E /COPYALL /zb /r:10 /w:10 /tee /unilog+:&amp;quot;D:\robocopylog.txt&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Add a domain to the global dns search list&lt;br /&gt;
 Set-DnsClientGlobalSetting -SuffixSearchList @(&amp;quot;corp.mariocorp.com&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Fix windows update not showing in the settings page (some RMM&#039;s do this by design to handle patching themselves)&lt;br /&gt;
 reg delete &amp;quot;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer&amp;quot; /v SettingsPageVisibility /f&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable Wi-Fi searching. This allows for more stable wi-fi performance at the cost of being able to see networks that pop up in realtime.&lt;br /&gt;
 netsh wlan set autoconfig enabled=no interface=&amp;quot;Wi-Fi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Enable Wi-Fi searching. This reverts the above command.&lt;br /&gt;
 netsh wlan set autoconfig enabled=yes interface=&amp;quot;Wi-Fi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Vim One-liner (Powershell only) (SYSTEM WIDE, NEEDS ADMIN)&lt;br /&gt;
 mkdir vim-install; cd vim-install; $ProgressPreference = &#039;SilentlyContinue&#039;; Invoke-Webrequest -UseBasicParsing https://github.com/vim/vim-win32-installer/releases/download/v9.1.0/gvim_9.1.0_x86_signed.zip -o gvim.zip; Expand-Archive -Path gvim.zip -DestinationPath .; cp .\vim\vim91\vim.exe C:\windows\system32\vim.exe&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Vim One-liner (Powershell only) (user only)&lt;br /&gt;
 mkdir vim-install; cd vim-install; $ProgressPreference = &#039;SilentlyContinue&#039;; Invoke-Webrequest -UseBasicParsing https://github.com/vim/vim-win32-installer/releases/download/v9.1.0/gvim_9.1.0_x86_signed.zip -o gvim.zip; Expand-Archive -Path gvim.zip -DestinationPath .; cp .\vim\vim91\vim.exe %localappdata%\Microsoft\WindowsApps\vim.exe&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Install Git One-liner&lt;br /&gt;
 winget install --id Git.Git -e --source winget --scope user&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set Hostname&lt;br /&gt;
 Rename-Computer -NewName &amp;quot;YourNewHostname&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Run Firefox with the profile selector screen&lt;br /&gt;
 &amp;quot;C:\Program Files\Mozilla Firefox\firefox.exe&amp;quot; --ProfileManager&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Delete all drive mappings / remove all network drives&lt;br /&gt;
 net use * /delete&lt;br /&gt;
&lt;br /&gt;
Ping with timestamp [powershell]&lt;br /&gt;
 ping google.com -t | % { &amp;quot;$(Get-Date -Format &#039;yyyy-MM-dd HH:mm:ss&#039;) $_&amp;quot; }&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1135</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1135"/>
		<updated>2026-02-25T02:10:08Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Configuration Files */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Erase Configurations ===&lt;br /&gt;
 erase startup-config&lt;br /&gt;
 delete flash:vlan.dat&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generate RSA Keys (1-liner) ===&lt;br /&gt;
 crypto key generate rsa general-keys modulus 1024&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Set the Root Bridge ===&lt;br /&gt;
The root bridge is the central switch in the spanning tree topology. It is chosen based on the lowest bridge priority. A lower priority value increases the likelihood of a switch becoming the root bridge.&lt;br /&gt;
&lt;br /&gt;
Set priority to influence root bridge selection:&lt;br /&gt;
* The default priority value is **32768** for all switches.&lt;br /&gt;
* Priority is set in increments of **4096**, and this value is added to the VLAN ID (e.g., for VLAN 1, the default bridge priority would be 32768).&lt;br /&gt;
&lt;br /&gt;
To influence the root bridge selection, change the priority value:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree vlan 1 priority 4096&lt;br /&gt;
  (Sets a lower priority value, increasing the likelihood of this switch becoming the root bridge for VLAN 1)&lt;br /&gt;
&lt;br /&gt;
Set the root bridge for a specific VLAN:&lt;br /&gt;
* To make the current switch the root bridge:&lt;br /&gt;
 spanning-tree vlan 1 root primary&lt;br /&gt;
  (This automatically sets the priority lower than the default value, typically to 24576, to ensure this switch becomes the root bridge)&lt;br /&gt;
&lt;br /&gt;
* To make the current switch the backup root bridge:&lt;br /&gt;
 spanning-tree vlan 1 root secondary&lt;br /&gt;
  (This sets the priority higher than the primary root, typically to 28672, making it the backup root bridge)&lt;br /&gt;
&lt;br /&gt;
Alternatively, manually set the root bridge priority:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree vlan 1 priority 24576&lt;br /&gt;
  (Sets this switch with a higher priority, making it more likely to become the root bridge)&lt;br /&gt;
&lt;br /&gt;
=== Verify Root Bridge ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree vlan 1&lt;br /&gt;
 (Shows the current root bridge and its priority, along with other STP details)&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches (this can cause network loops).&lt;br /&gt;
* PortFast should only be used on access/edge ports that connect to end devices like PCs, printers, or phones.&lt;br /&gt;
* Incorrect use of PortFast can cause Layer 2 loops.&lt;br /&gt;
* The default priority value is **32768**, and it is adjusted in increments of **4096**.&lt;br /&gt;
* Lower priority values increase the likelihood of becoming the root bridge.&lt;br /&gt;
* The priority value combined with the MAC address (if priorities are equal) is used to determine the root bridge.&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using the default administrative distance value.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network and specify the administrative distance.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Fully Specified Static Route ===&lt;br /&gt;
A fully specified static route includes both the next-hop IP address and the exit interface. This is commonly used on multi-access networks.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
You can also specify the administrative distance:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;exit-interface&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1134</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1134"/>
		<updated>2026-02-25T01:52:15Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Spanning Tree */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generate RSA Keys (1-liner) ===&lt;br /&gt;
 crypto key generate rsa general-keys modulus 1024&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Set the Root Bridge ===&lt;br /&gt;
The root bridge is the central switch in the spanning tree topology. It is chosen based on the lowest bridge priority. A lower priority value increases the likelihood of a switch becoming the root bridge.&lt;br /&gt;
&lt;br /&gt;
Set priority to influence root bridge selection:&lt;br /&gt;
* The default priority value is **32768** for all switches.&lt;br /&gt;
* Priority is set in increments of **4096**, and this value is added to the VLAN ID (e.g., for VLAN 1, the default bridge priority would be 32768).&lt;br /&gt;
&lt;br /&gt;
To influence the root bridge selection, change the priority value:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree vlan 1 priority 4096&lt;br /&gt;
  (Sets a lower priority value, increasing the likelihood of this switch becoming the root bridge for VLAN 1)&lt;br /&gt;
&lt;br /&gt;
Set the root bridge for a specific VLAN:&lt;br /&gt;
* To make the current switch the root bridge:&lt;br /&gt;
 spanning-tree vlan 1 root primary&lt;br /&gt;
  (This automatically sets the priority lower than the default value, typically to 24576, to ensure this switch becomes the root bridge)&lt;br /&gt;
&lt;br /&gt;
* To make the current switch the backup root bridge:&lt;br /&gt;
 spanning-tree vlan 1 root secondary&lt;br /&gt;
  (This sets the priority higher than the primary root, typically to 28672, making it the backup root bridge)&lt;br /&gt;
&lt;br /&gt;
Alternatively, manually set the root bridge priority:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree vlan 1 priority 24576&lt;br /&gt;
  (Sets this switch with a higher priority, making it more likely to become the root bridge)&lt;br /&gt;
&lt;br /&gt;
=== Verify Root Bridge ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree vlan 1&lt;br /&gt;
 (Shows the current root bridge and its priority, along with other STP details)&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches (this can cause network loops).&lt;br /&gt;
* PortFast should only be used on access/edge ports that connect to end devices like PCs, printers, or phones.&lt;br /&gt;
* Incorrect use of PortFast can cause Layer 2 loops.&lt;br /&gt;
* The default priority value is **32768**, and it is adjusted in increments of **4096**.&lt;br /&gt;
* Lower priority values increase the likelihood of becoming the root bridge.&lt;br /&gt;
* The priority value combined with the MAC address (if priorities are equal) is used to determine the root bridge.&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using the default administrative distance value.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network and specify the administrative distance.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Fully Specified Static Route ===&lt;br /&gt;
A fully specified static route includes both the next-hop IP address and the exit interface. This is commonly used on multi-access networks.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
You can also specify the administrative distance:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;exit-interface&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1133</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1133"/>
		<updated>2026-02-25T01:50:58Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Spanning Tree */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generate RSA Keys (1-liner) ===&lt;br /&gt;
 crypto key generate rsa general-keys modulus 1024&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Set the Root Bridge ===&lt;br /&gt;
Define a root bridge to control the topology and ensure consistent path selection.&lt;br /&gt;
&lt;br /&gt;
Set priority to influence root bridge selection:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree vlan 1 priority 4096&lt;br /&gt;
&lt;br /&gt;
Set the root bridge for a specific VLAN:&lt;br /&gt;
 spanning-tree vlan 1 root primary&lt;br /&gt;
  (This sets the local switch as the root bridge)&lt;br /&gt;
&lt;br /&gt;
Alternatively, set it to secondary:&lt;br /&gt;
 spanning-tree vlan 1 root secondary&lt;br /&gt;
  (This sets the local switch to be the backup root bridge)&lt;br /&gt;
&lt;br /&gt;
=== Verify Root Bridge ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree vlan 1&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
* Root Bridge selection can impact the STP topology and performance&lt;br /&gt;
* Lower priority values increase the chance of becoming the root bridge&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using the default administrative distance value.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network and specify the administrative distance.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Fully Specified Static Route ===&lt;br /&gt;
A fully specified static route includes both the next-hop IP address and the exit interface. This is commonly used on multi-access networks.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
You can also specify the administrative distance:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;exit-interface&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1110</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1110"/>
		<updated>2026-02-20T01:55:36Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* DHCP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1109</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1109"/>
		<updated>2026-02-20T01:04:20Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Assign IPv4 Default Gateway (Router) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1108</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1108"/>
		<updated>2026-02-20T01:04:08Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Assign IPv4 Default Gateway (Router) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1107</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1107"/>
		<updated>2026-02-20T01:03:45Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Configure a Default Route */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Router) ===&lt;br /&gt;
 ip default-network 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1106</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1106"/>
		<updated>2026-02-20T01:00:05Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Router) ===&lt;br /&gt;
 ip default-network 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1105</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1105"/>
		<updated>2026-02-20T00:59:36Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Assign IPv4 Default Gateway */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1104</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1104"/>
		<updated>2026-02-20T00:18:18Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1103</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1103"/>
		<updated>2026-02-20T00:17:41Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Interface IPv4 Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1102</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1102"/>
		<updated>2026-02-20T00:17:27Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* IPv6 Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv4 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1101</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1101"/>
		<updated>2026-02-20T00:17:10Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv4 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1100</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1100"/>
		<updated>2026-02-20T00:16:29Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1099</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1099"/>
		<updated>2026-02-20T00:15:44Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1094</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1094"/>
		<updated>2026-02-18T00:57:52Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Enter Privileged Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1093</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1093"/>
		<updated>2026-02-18T00:56:59Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Filter Running Config (grep-like) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1092</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1092"/>
		<updated>2026-02-18T00:55:12Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1091</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1091"/>
		<updated>2026-02-18T00:54:48Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1090</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1090"/>
		<updated>2026-02-18T00:54:21Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1089</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1089"/>
		<updated>2026-02-18T00:47:59Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
=== Static Routing ===&lt;br /&gt;
&lt;br /&gt;
==== Configure a Static Route ====&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:  &lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Configure a Default Route ====&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
=== Dynamic Routing ===&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
==== Configure RIP v2 ====&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
 version 2&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== Configure EIGRP ====&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
==== Configure OSPF ====&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
=== Route Summarization ===&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:  &lt;br /&gt;
192.168.0.0/24  &lt;br /&gt;
192.168.1.0/24  &lt;br /&gt;
192.168.2.0/24  &lt;br /&gt;
192.168.3.0/24  &lt;br /&gt;
&lt;br /&gt;
Can be summarized as:  &lt;br /&gt;
192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (EIGRP) ====&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (OSPF ABR) ====&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
 area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Route Summarization (EIGRP Example) ====&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;br /&gt;
&lt;br /&gt;
=== Administrative Distance ===&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:  &lt;br /&gt;
Connected – 0  &lt;br /&gt;
Static – 1  &lt;br /&gt;
EIGRP – 90  &lt;br /&gt;
OSPF – 110  &lt;br /&gt;
RIP – 120&lt;br /&gt;
&lt;br /&gt;
=== Show Routing Information ===&lt;br /&gt;
&lt;br /&gt;
==== View Routing Table ====&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
==== View Specific Route ====&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== View Routing Protocol Information ====&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1088</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1088"/>
		<updated>2026-02-18T00:47:06Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
    ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
    ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
=== Static Routing ===&lt;br /&gt;
&lt;br /&gt;
==== Configure a Static Route ====&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
    ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:  &lt;br /&gt;
    ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Configure a Default Route ====&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
    ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
=== Dynamic Routing ===&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
==== Configure RIP v2 ====&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
    router rip&lt;br /&gt;
    version 2&lt;br /&gt;
    no auto-summary&lt;br /&gt;
    network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== Configure EIGRP ====&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
    router eigrp 100&lt;br /&gt;
    no auto-summary&lt;br /&gt;
    network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
==== Configure OSPF ====&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
    router ospf 1&lt;br /&gt;
    network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
=== Route Summarization ===&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:  &lt;br /&gt;
192.168.0.0/24  &lt;br /&gt;
192.168.1.0/24  &lt;br /&gt;
192.168.2.0/24  &lt;br /&gt;
192.168.3.0/24  &lt;br /&gt;
&lt;br /&gt;
Can be summarized as:  &lt;br /&gt;
192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (EIGRP) ====&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
    interface GigabitEthernet0/0&lt;br /&gt;
    ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (OSPF ABR) ====&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
    router ospf 1&lt;br /&gt;
    area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Route Summarization (EIGRP Example) ====&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
    interface GigabitEthernet0/0&lt;br /&gt;
    ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;br /&gt;
&lt;br /&gt;
=== Administrative Distance ===&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:  &lt;br /&gt;
Connected – 0  &lt;br /&gt;
Static – 1  &lt;br /&gt;
EIGRP – 90  &lt;br /&gt;
OSPF – 110  &lt;br /&gt;
RIP – 120&lt;br /&gt;
&lt;br /&gt;
=== Show Routing Information ===&lt;br /&gt;
&lt;br /&gt;
==== View Routing Table ====&lt;br /&gt;
&lt;br /&gt;
    show ip route&lt;br /&gt;
&lt;br /&gt;
==== View Specific Route ====&lt;br /&gt;
&lt;br /&gt;
    show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== View Routing Protocol Information ====&lt;br /&gt;
&lt;br /&gt;
    show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1087</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1087"/>
		<updated>2026-02-18T00:45:14Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: Undo revision 1086 by 209.87.206.13 (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
=== Static Routing ===&lt;br /&gt;
&lt;br /&gt;
==== Configure a Static Route ====&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Configure a Default Route ====&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
=== Dynamic Routing ===&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
==== Configure RIP v2 ====&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
router rip&lt;br /&gt;
version 2&lt;br /&gt;
no auto-summary&lt;br /&gt;
network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== Configure EIGRP ====&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
router eigrp 100&lt;br /&gt;
no auto-summary&lt;br /&gt;
network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
==== Configure OSPF ====&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
router ospf 1&lt;br /&gt;
network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
=== Route Summarization ===&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
192.168.0.0/24&lt;br /&gt;
192.168.1.0/24&lt;br /&gt;
192.168.2.0/24&lt;br /&gt;
192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (EIGRP) ====&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
interface GigabitEthernet0/0&lt;br /&gt;
ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (OSPF ABR) ====&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
router ospf 1&lt;br /&gt;
area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Route Summarization (EIGRP Example) ====&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
interface GigabitEthernet0/0&lt;br /&gt;
ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;br /&gt;
&lt;br /&gt;
=== Administrative Distance ===&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
Connected – 0&lt;br /&gt;
Static – 1&lt;br /&gt;
EIGRP – 90&lt;br /&gt;
OSPF – 110&lt;br /&gt;
RIP – 120&lt;br /&gt;
&lt;br /&gt;
=== Show Routing Information ===&lt;br /&gt;
&lt;br /&gt;
==== View Routing Table ====&lt;br /&gt;
&lt;br /&gt;
show ip route&lt;br /&gt;
&lt;br /&gt;
==== View Specific Route ====&lt;br /&gt;
&lt;br /&gt;
show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== View Routing Protocol Information ====&lt;br /&gt;
&lt;br /&gt;
show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1086</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1086"/>
		<updated>2026-02-18T00:44:29Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1085</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1085"/>
		<updated>2026-02-18T00:42:32Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
=== Static Routing ===&lt;br /&gt;
&lt;br /&gt;
==== Configure a Static Route ====&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Configure a Default Route ====&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
=== Dynamic Routing ===&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
==== Configure RIP v2 ====&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
router rip&lt;br /&gt;
version 2&lt;br /&gt;
no auto-summary&lt;br /&gt;
network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== Configure EIGRP ====&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
router eigrp 100&lt;br /&gt;
no auto-summary&lt;br /&gt;
network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
==== Configure OSPF ====&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
router ospf 1&lt;br /&gt;
network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
=== Route Summarization ===&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
192.168.0.0/24&lt;br /&gt;
192.168.1.0/24&lt;br /&gt;
192.168.2.0/24&lt;br /&gt;
192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (EIGRP) ====&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
interface GigabitEthernet0/0&lt;br /&gt;
ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Manual Summarization (OSPF ABR) ====&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
router ospf 1&lt;br /&gt;
area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
==== Configure Route Summarization (EIGRP Example) ====&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
interface GigabitEthernet0/0&lt;br /&gt;
ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;br /&gt;
&lt;br /&gt;
=== Administrative Distance ===&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
Connected – 0&lt;br /&gt;
Static – 1&lt;br /&gt;
EIGRP – 90&lt;br /&gt;
OSPF – 110&lt;br /&gt;
RIP – 120&lt;br /&gt;
&lt;br /&gt;
=== Show Routing Information ===&lt;br /&gt;
&lt;br /&gt;
==== View Routing Table ====&lt;br /&gt;
&lt;br /&gt;
show ip route&lt;br /&gt;
&lt;br /&gt;
==== View Specific Route ====&lt;br /&gt;
&lt;br /&gt;
show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
==== View Routing Protocol Information ====&lt;br /&gt;
&lt;br /&gt;
show ip protocols&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1084</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1084"/>
		<updated>2026-02-18T00:39:46Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Routing Table */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1083</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1083"/>
		<updated>2026-02-18T00:29:34Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Enable IP Routing (Layer 3 Switch) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1082</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1082"/>
		<updated>2026-02-18T00:29:15Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* System &amp;amp; Routing Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1081</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1081"/>
		<updated>2026-02-18T00:27:58Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Port Security */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Routing ==&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1080</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1080"/>
		<updated>2026-02-18T00:26:23Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Configure Route Summarization (EIGRP Example) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
 ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1079</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1079"/>
		<updated>2026-02-18T00:26:12Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
== Configure Route Summarization (EIGRP Example) ==&lt;br /&gt;
Reduces routing table size by advertising a single summary route instead of multiple specific networks.&lt;br /&gt;
&lt;br /&gt;
interface GigabitEthernet0/0&lt;br /&gt;
ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
Replace **100** with your EIGRP AS number, and adjust the network address and subnet mask to match your summary range.&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1078</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1078"/>
		<updated>2026-02-18T00:15:00Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=WAP_Arrangement&amp;diff=1068</id>
		<title>WAP Arrangement</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=WAP_Arrangement&amp;diff=1068"/>
		<updated>2026-02-04T02:32:03Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: Created page with &amp;quot;= Wi-Fi Access Point Placement for 2.4 GHz and 5 GHz =  This page provides guidelines for placing Wi-Fi access points (APs) to optimize coverage and performance for both 2.4 GHz and 5 GHz bands.  == Overview == Wi-Fi networks commonly operate on two frequency bands: 2.4 GHz and 5 GHz. Each band has different characteristics:  {| class=&amp;quot;wikitable&amp;quot; ! Feature !! 2.4 GHz !! 5 GHz |- | Range || Long, penetrates walls better || Short, limited range |- | Speed |...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Wi-Fi Access Point Placement for 2.4 GHz and 5 GHz =&lt;br /&gt;
&lt;br /&gt;
This page provides guidelines for placing Wi-Fi access points (APs) to optimize coverage and performance for both 2.4 GHz and 5 GHz bands.&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
Wi-Fi networks commonly operate on two frequency bands: 2.4 GHz and 5 GHz. Each band has different characteristics:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Feature !! 2.4 GHz !! 5 GHz&lt;br /&gt;
|-&lt;br /&gt;
| Range || Long, penetrates walls better || Short, limited range&lt;br /&gt;
|-&lt;br /&gt;
| Speed || Slower, more crowded || Faster, less interference&lt;br /&gt;
|-&lt;br /&gt;
| Interference || Common (Wi-Fi, Bluetooth, microwaves) || Less crowded&lt;br /&gt;
|-&lt;br /&gt;
| Best Use || General coverage || High-speed connections nearby&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== General Placement Guidelines ==&lt;br /&gt;
# Place APs in a **central location** within the coverage area.&lt;br /&gt;
# Mount APs **high on walls or ceilings** for better signal distribution.&lt;br /&gt;
# Avoid obstacles such as **metal, mirrors, thick walls, and microwaves**.&lt;br /&gt;
# Consider **band steering** or separate coverage planning for 2.4 GHz and 5 GHz.&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Band-Specific Guidelines ==&lt;br /&gt;
&lt;br /&gt;
=== 2.4 GHz ===&lt;br /&gt;
* Longer range; fewer APs needed.&lt;br /&gt;
* 10–15% coverage overlap is sufficient for roaming.&lt;br /&gt;
* Works well through walls and floors.&lt;br /&gt;
* Suitable for broad coverage areas.&lt;br /&gt;
&lt;br /&gt;
=== 5 GHz ===&lt;br /&gt;
* Shorter range; APs should be closer to users.&lt;br /&gt;
* Direct line-of-sight provides best performance.&lt;br /&gt;
* 20–30% overlap recommended for seamless roaming.&lt;br /&gt;
* Ideal for high-density areas requiring fast connections.&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Channel Planning ==&lt;br /&gt;
* 2.4 GHz: Use channels **1, 6, or 11** (non-overlapping).&lt;br /&gt;
* 5 GHz: Use available channels avoiding DFS if devices do not support them.&lt;br /&gt;
* Proper channel planning reduces interference and improves performance.&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Practical Layout Tips ==&lt;br /&gt;
* **Small home**: One centrally located AP can cover both bands.&lt;br /&gt;
* **Medium home / small office**: Place one AP per floor; 2.4 GHz covers distant rooms, 5 GHz covers nearby rooms.&lt;br /&gt;
* **Large office / multi-floor building**: Conduct a site survey; place 5 GHz APs ~25–30 feet apart, 2.4 GHz APs further apart.&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [Wi-Fi Alliance – Wi-Fi 6](https://www.wi-fi.org/discover-wi-fi)&lt;br /&gt;
* [Cisco – Wireless LAN Design Guidelines](https://www.cisco.com/c/en/us/solutions/enterprise-networks/wireless.html)&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1067</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1067"/>
		<updated>2026-02-04T02:29:05Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1066</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1066"/>
		<updated>2026-02-04T01:01:13Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Configure DHCP Snooping rate limiting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1065</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1065"/>
		<updated>2026-02-04T00:57:10Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1064</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1064"/>
		<updated>2026-02-04T00:55:05Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1063</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1063"/>
		<updated>2026-02-04T00:44:37Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Spanning Tree */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1062</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1062"/>
		<updated>2026-02-04T00:41:29Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Encrypt Plaintext Passwords (Weak Encryption) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
=== Enable portfast on an interface ===&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1061</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1061"/>
		<updated>2026-02-04T00:39:01Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
=== Enable portfast on an interface ===&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1060</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1060"/>
		<updated>2026-02-04T00:27:54Z</updated>

		<summary type="html">&lt;p&gt;209.87.206.13: /* Port Security */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>209.87.206.13</name></author>
	</entry>
</feed>