Cisco IOS Patterns
Use this skill to review Cisco IOS or IOS-XE config. It can also help build a safe change plan or gather facts without making an issue worse.
Use This Skill When
- Reviewing a planned IOS or IOS-XE change.
- Picking safe, read-only
showcommands. - Checking ACL rules, wildcard masks, order, and direction.
- Explaining global, interface, router, and line config modes.
- Checking that a change works before it is saved.
Safety Rules
Treat all commands as examples. Do not assume they fit a live device.
Before a change, check:
- The device model and IOS version.
- The exact interface names.
- The current config and state.
- How you will undo the change.
- Whether you have console or out-of-band access.
- Whether the change has approval.
- Whether the device is part of a stack, pair, or failover group.
Do not change a live device unless the user clearly asks for it. Start with read-only checks.
Use this order:
- Save facts about the current state.
- Review the exact new config.
- Check that admin access will still work.
- Apply the smallest needed change.
- Run the same checks again.
- Compare the new state with the old state.
- Test the rollback plan if the change fails.
- Save the config only after the checks pass.
Do not reload a device as a test. Do not use write erase, erase startup-config, reload, or broad no commands unless the user clearly asks and the risk is known.
Config Modes
Router> enable
Router# show running-config
Router# configure terminal
Router(config)# interface GigabitEthernet0/1
Router(config-if)# description UPLINK-TO-CORE
Router(config-if)# no shutdown
Router(config-if)# exit
Router(config)# end
Router# show running-config interface GigabitEthernet0/1Common prompts:
Router> User mode
Router# Privileged mode
Router(config)# Global config mode
Router(config-if)# Interface config mode
Router(config-router)# Router config mode
Router(config-line)# Line config moderunning-config is the active config in memory. startup-config is used after a restart.
A device may accept a bad command. Do not save just because the command worked. Check the result first. If the change is approved and tests pass, save it with:
copy running-config startup-configSome devices support show archive config differences or config replace tools. Check support before using them.
Read-Only Checks
Pick only the commands needed for the task.
show clock
show version
show inventory
show processes cpu sorted
show memory statistics
show logging
show running-config | section line vty
show running-config | section interface
show running-config | section router bgp
show ip interface brief
show interfaces
show interfaces status
show vlan brief
show mac address-table
show spanning-tree
show ip route
show ip protocols
show ip access-lists
show route-map
show ip prefix-listCommand support and output can change by model and IOS release. If a command fails, check show version and use ? to find the right form.
Some show commands can make a busy device work harder. Avoid large output, deep debug commands, and fast repeat loops. Use filters such as | include, | exclude, | begin, and | section when supported.
Do not paste a full config into a ticket by default. It may hold passwords, keys, customer names, SNMP data, or private network details. Gather only the needed parts. Hide secret values before sharing them.
Wildcard Masks
IOS ACLs and many route rules use wildcard masks. A wildcard mask is not a subnet mask.
Subnet mask Wildcard mask
255.255.255.255 0.0.0.0
255.255.255.252 0.0.0.3
255.255.255.0 0.0.0.255
255.255.0.0 0.0.255.255A 0 bit must match. A 1 bit can differ.
Check each wildcard mask before use. A subnet mask used in the wildcard field may match the wrong hosts.
Also check for these cases:
host 192.0.2.10means192.0.2.10 0.0.0.0.anymeans all addresses.- Non-stop wildcard masks, such as
0.0.5.255, can be valid but are easy to get wrong. - IPv6 ACLs use prefix lengths, not IPv4 wildcard masks.
ACL Review
Review the ACL from top to bottom. The first match wins. Most ACLs have an unseen deny rule at the end.
ip access-list extended WEB-IN
10 permit tcp 192.0.2.0 0.0.0.255 any eq 443
999 deny ip any any logFor each ACL, check:
- Source and target addresses.
- Source and target ports.
- Rule order and sequence numbers.
- The unseen final deny.
- The interface where the ACL is used.
- The
inoroutdirection. - Return traffic and state rules.
- DHCP, DNS, routing, and admin traffic.
- Object groups or time ranges, if used.
- Hit counts before and after the change.
- Whether logs could flood the device.
Do not assume in means traffic entering the network. It means traffic entering that interface. Draw the packet path if the direction is not clear.
Use these checks when supported:
show ip access-lists WEB-IN
show running-config | include ip access-group
show running-config interface GigabitEthernet0/1Interface Health
Before and after an interface change, check:
show ip interface brief
show interfaces GigabitEthernet0/1
show running-config interface GigabitEthernet0/1Look for:
- Admin and line state.
- Speed and duplex.
- Input and output errors.
- Drops and queue errors.
- CRC errors.
- MTU.
- IP address and mask.
- ACL direction.
- Switchport mode and VLAN.
- Port channel membership.
- Recent link changes.
Do not use no shutdown until you know what is linked to the port. A shut port may be shut for safety.
Concrete Example
Goal: Allow HTTPS from 192.0.2.0/24 into a server VLAN on GigabitEthernet0/1.
First, gather the current state:
show clock
show version
show ip interface brief
show running-config interface GigabitEthernet0/1
show ip access-lists WEB-IN
show logging | include GigabitEthernet0/1|WEB-INReview the planned rule:
ip access-list extended WEB-IN
10 permit tcp 192.0.2.0 0.0.0.255 any eq 443Check these facts before use:
0.0.0.255matches the full/24.- The target should be
anyonly if that wide match is planned. - Rule 10 must not sit below a deny that blocks it.
- The ACL must be placed on the right interface.
- The chosen direction must match the packet path.
- Admin access and needed return traffic must still work.
After the change, check:
show ip access-lists WEB-IN
show running-config interface GigabitEthernet0/1
show interfaces GigabitEthernet0/1
show logging | include GigabitEthernet0/1|WEB-INTest HTTPS from an allowed host. Test from a host that should be blocked. Compare ACL hit counts. If the checks fail, remove only the new rule or use the approved rollback plan. Save only after all checks pass.