---
name: cisco-ios-patterns
description: Review Cisco IOS and IOS-XE show commands, config modes, wildcard masks, ACL placement, interface health, and safe change checks.
origin: community
---

# Cisco IOS Patterns

Use this skill to review Cisco IOS or IOS-XE config. It can also help build a safe change plan or gather facts without making an issue worse.

## Use This Skill When

- Reviewing a planned IOS or IOS-XE change.
- Picking safe, read-only `show` commands.
- Checking ACL rules, wildcard masks, order, and direction.
- Explaining global, interface, router, and line config modes.
- Checking that a change works before it is saved.

## Safety Rules

Treat all commands as examples. Do not assume they fit a live device.

Before a change, check:

- The device model and IOS version.
- The exact interface names.
- The current config and state.
- How you will undo the change.
- Whether you have console or out-of-band access.
- Whether the change has approval.
- Whether the device is part of a stack, pair, or failover group.

Do not change a live device unless the user clearly asks for it. Start with read-only checks.

Use this order:

1. Save facts about the current state.
2. Review the exact new config.
3. Check that admin access will still work.
4. Apply the smallest needed change.
5. Run the same checks again.
6. Compare the new state with the old state.
7. Test the rollback plan if the change fails.
8. Save the config only after the checks pass.

Do not reload a device as a test. Do not use `write erase`, `erase startup-config`, `reload`, or broad `no` commands unless the user clearly asks and the risk is known.

## Config Modes

```text
Router> enable
Router# show running-config
Router# configure terminal
Router(config)# interface GigabitEthernet0/1
Router(config-if)# description UPLINK-TO-CORE
Router(config-if)# no shutdown
Router(config-if)# exit
Router(config)# end
Router# show running-config interface GigabitEthernet0/1
```

Common prompts:

```text
Router>          User mode
Router#          Privileged mode
Router(config)#  Global config mode
Router(config-if)# Interface config mode
Router(config-router)# Router config mode
Router(config-line)# Line config mode
```

`running-config` is the active config in memory. `startup-config` is used after a restart.

A device may accept a bad command. Do not save just because the command worked. Check the result first. If the change is approved and tests pass, save it with:

```text
copy running-config startup-config
```

Some devices support `show archive config differences` or config replace tools. Check support before using them.

## Read-Only Checks

Pick only the commands needed for the task.

```text
show clock
show version
show inventory
show processes cpu sorted
show memory statistics
show logging
show running-config | section line vty
show running-config | section interface
show running-config | section router bgp
show ip interface brief
show interfaces
show interfaces status
show vlan brief
show mac address-table
show spanning-tree
show ip route
show ip protocols
show ip access-lists
show route-map
show ip prefix-list
```

Command support and output can change by model and IOS release. If a command fails, check `show version` and use `?` to find the right form.

Some `show` commands can make a busy device work harder. Avoid large output, deep debug commands, and fast repeat loops. Use filters such as `| include`, `| exclude`, `| begin`, and `| section` when supported.

Do not paste a full config into a ticket by default. It may hold passwords, keys, customer names, SNMP data, or private network details. Gather only the needed parts. Hide secret values before sharing them.

## Wildcard Masks

IOS ACLs and many route rules use wildcard masks. A wildcard mask is not a subnet mask.

```text
Subnet mask       Wildcard mask
255.255.255.255   0.0.0.0
255.255.255.252   0.0.0.3
255.255.255.0     0.0.0.255
255.255.0.0       0.0.255.255
```

A `0` bit must match. A `1` bit can differ.

Check each wildcard mask before use. A subnet mask used in the wildcard field may match the wrong hosts.

Also check for these cases:

- `host 192.0.2.10` means `192.0.2.10 0.0.0.0`.
- `any` means all addresses.
- Non-stop wildcard masks, such as `0.0.5.255`, can be valid but are easy to get wrong.
- IPv6 ACLs use prefix lengths, not IPv4 wildcard masks.

## ACL Review

Review the ACL from top to bottom. The first match wins. Most ACLs have an unseen deny rule at the end.

```text
ip access-list extended WEB-IN
  10 permit tcp 192.0.2.0 0.0.0.255 any eq 443
  999 deny ip any any log
```

For each ACL, check:

- Source and target addresses.
- Source and target ports.
- Rule order and sequence numbers.
- The unseen final deny.
- The interface where the ACL is used.
- The `in` or `out` direction.
- Return traffic and state rules.
- DHCP, DNS, routing, and admin traffic.
- Object groups or time ranges, if used.
- Hit counts before and after the change.
- Whether logs could flood the device.

Do not assume `in` means traffic entering the network. It means traffic entering that interface. Draw the packet path if the direction is not clear.

Use these checks when supported:

```text
show ip access-lists WEB-IN
show running-config | include ip access-group
show running-config interface GigabitEthernet0/1
```

## Interface Health

Before and after an interface change, check:

```text
show ip interface brief
show interfaces GigabitEthernet0/1
show running-config interface GigabitEthernet0/1
```

Look for:

- Admin and line state.
- Speed and duplex.
- Input and output errors.
- Drops and queue errors.
- CRC errors.
- MTU.
- IP address and mask.
- ACL direction.
- Switchport mode and VLAN.
- Port channel membership.
- Recent link changes.

Do not use `no shutdown` until you know what is linked to the port. A shut port may be shut for safety.

## Concrete Example

Goal: Allow HTTPS from `192.0.2.0/24` into a server VLAN on `GigabitEthernet0/1`.

First, gather the current state:

```text
show clock
show version
show ip interface brief
show running-config interface GigabitEthernet0/1
show ip access-lists WEB-IN
show logging | include GigabitEthernet0/1|WEB-IN
```

Review the planned rule:

```text
ip access-list extended WEB-IN
  10 permit tcp 192.0.2.0 0.0.0.255 any eq 443
```

Check these facts before use:

- `0.0.0.255` matches the full `/24`.
- The target should be `any` only if that wide match is planned.
- Rule 10 must not sit below a deny that blocks it.
- The ACL must be placed on the right interface.
- The chosen direction must match the packet path.
- Admin access and needed return traffic must still work.

After the change, check:

```text
show ip access-lists WEB-IN
show running-config interface GigabitEthernet0/1
show interfaces GigabitEthernet0/1
show logging | include GigabitEthernet0/1|WEB-IN
```

Test HTTPS from an allowed host. Test from a host that should be blocked. Compare ACL hit counts. If the checks fail, remove only the new rule or use the approved rollback plan. Save only after all checks pass.