IOS CLI access, mode navigation

Ways to reach the CLI

Any CLI session, however you got there, is an EXEC session.

IOS is modal: distinct modes, each with its own command set and command history, arranged in a hierarchy from least to most specific. You enter a more specific mode from the one above it.

Interface commands only exist in interface config mode, so the full path there is: user EXEC > privileged EXEC > global config > interface config. Commands entered in interface config mode apply only to the interface you selected.

Mode navigation

Rules of thumb: exit is back one level, while end and Ctrl+Z are back to privileged EXEC from any config mode. Help (?) only shows commands valid at your current prompt.

You do not have to exit back to global config to switch interfaces. From (config-if) just type interface Ethernet 0/1 and you’re configuring the new one. The prompt won’t change (it doesn’t show which interface), so keep track of where you are.

Context-sensitive help

Odds and ends from the lab demo

Default VLANs on a switch: VLAN 1 and 1002-1005 exist out of the box, reserved, and can’t be deleted.

SSH’d in? You won’t see syslog messages unless you run terminal monitor.

User EXEC is junior admin and server admin territory; privileged EXEC is the network engineer’s mode. Remote logins often drop you straight into privileged.

Configuration files

A config file is just the IOS commands that tell the device what to do. startup-config is the dedicated file read and parsed at boot; running-config is the live config in memory, where commands you type at the CLI execute immediately and land.

Reading a config: sections are separated by ! lines. Global commands sit at the left margin (hostname, spanning-tree mode, ip default-gateway, ntp server); indented lines belong to the block above them (an interface’s switchport mode, description, ip address).