↓ Skip to main content
  1. Router and Switch Articles/
  2. IOS-XE/

IOS XE Interface Configuration (shutdown / no shutdown) and Verification

Table of Contents

Shutting Down and Bringing Up an Interface on Cisco IOS XE

shutdown administratively takes an interface down and no shutdown brings it back. Both are entered in interface configuration mode and take effect as soon as end is entered. Once an interface is shut down, all traffic that uses it stops. This article connects two routers back to back and confirms on real devices that a working ping stops once one side is shut down.

Shutting Down an Interface on Cisco IOS XE
interface [INTERFACE_NAME]
 shutdown
Bringing Up an Interface on Cisco IOS XE
interface [INTERFACE_NAME]
 no shutdown
FieldValue
[INTERFACE_NAME]The target interface (e.g. GigabitEthernet1)

There Are Two States

The first line of show interfaces shows two states. The first is Layer 1 (physical) and the second is Layer 2 (data link).

GigabitEthernet1 is up, line protocol is up
                 ~~~~~~  ~~~~~~~~~~~~~~~~~~
               Layer 1          Layer 2
Layer 1Layer 2Meaning
administratively downdownShut down by configuration
upupBrought up, and the link is established
updownBrought up, but there is a problem on the far side or the cable

administratively down means “taken down by configuration”, which distinguishes it from a down caused by a cable fault. When isolating a fault, look at these two states first.

Verification Commands

CommandWhat it shows
show interfaces [INTERFACE_NAME]Details of one interface: state, MAC address, IP address, MTU, counters
show ip interface briefOne line per interface. Status is Layer 1 and Protocol is Layer 2
show interfaces descriptionA list of interface names, states and descriptions
show running-config interface [INTERFACE_NAME]The configuration of that interface

There is no show interfaces brief command on IOS XE. Use show ip interface brief for a list.

Verification Topology

Two Catalyst 8000V routers are connected back to back on GigabitEthernet1 with 192.168.0.0/24. No routing protocol is configured; only reachability within the directly connected segment is examined.

RouterInterfaceAddress
XE1GigabitEthernet1192.168.0.1/24
XE2GigabitEthernet1192.168.0.2/24

Overview of the Steps

STEPActionWhat to confirm
0Initial stateBoth sides are up/up and the ping from XE1 to XE2 succeeds
1Shut down GigabitEthernet1 on XE1XE1 becomes administratively down/down and the ping stops working. How the far end, XE2, looks
2Bring GigabitEthernet1 on XE1 back up (final state)It returns to up/up and the ping succeeds again

Reachability is measured at each step with ping 192.168.0.2 from XE1.

STEP 0: The Interface Is Up and the Ping Succeeds

show ip interface brief lists the state of every interface. Status is Layer 1 and Protocol is Layer 2.

STEP 0 XE1 show ip interface brief
XE1#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet1       192.168.0.1     YES TFTP   up                    up      
GigabitEthernet2       unassigned      YES unset  administratively down down    
GigabitEthernet3       unassigned      YES unset  administratively down down    
GigabitEthernet4       10.19.14.11     YES TFTP   up                    up      

GigabitEthernet2 and 3 are unused and remain shut down. An unused interface showing administratively down is normal, not a fault.

Fifty pings are sent from XE1 to XE2.

STEP 0 XE1 ping 192.168.0.2
XE1#ping 192.168.0.2 source GigabitEthernet1 repeat 50 timeout 1
Type escape sequence to abort.
Sending 50, 100-byte ICMP Echos to 192.168.0.2, timeout is 1 seconds:
Packet sent with a source address of 192.168.0.1 
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (50/50), round-trip min/avg/max = 2/3/7 ms

! is a success and . is a timeout. All fifty succeeded.

STEP 1: Shutting It Down Stops the Ping

GigabitEthernet1 on XE1 is shut down.

STEP 1 XE1 applying shutdown
XE1#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
XE1(config)#interface GigabitEthernet1
XE1(config-if)# shutdown
XE1(config-if)#end

The state changes to administratively down/down. Note that the IP address is still configured. Shutting an interface down only stops it; it does not remove the configuration.

STEP 1 XE1 show ip interface brief
XE1#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet1       192.168.0.1     YES TFTP   administratively down down    
GigabitEthernet2       unassigned      YES unset  administratively down down    
GigabitEthernet3       unassigned      YES unset  administratively down down    
GigabitEthernet4       10.19.14.11     YES TFTP   up                    up      

The detailed output of show interfaces says the same thing.

STEP 1 XE1 show interfaces GigabitEthernet1
XE1#show interfaces GigabitEthernet1
GigabitEthernet1 is administratively down, line protocol is down 
  Hardware is vNIC, address is 5254.0050.04f9 (bia 5254.0050.04f9)
  Description: to GigabitEthernet1.XE2
  Internet address is 192.168.0.1/24
  MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec, 

Two lines appear in the syslog. Layer 1 first, then Layer 2, about a second apart.

STEP 1 XE1 syslog
*Sep 12 06:28:04.079: %LINK-5-CHANGED: Interface GigabitEthernet1, changed state to administratively down
*Sep 12 06:28:05.080: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1, changed state to down

Because %LINK-5-CHANGED says administratively down, the log alone tells you whether the interface was taken down by configuration or went down on its own. A cable fault produces changed state to down instead.

The Ping Stops Working

Running the same ping after the shutdown, the command itself is rejected.

STEP 1 XE1 ping (with source)
XE1#ping 192.168.0.2 source GigabitEthernet1 repeat 50 timeout 1
% Invalid source interface - IP not enabled or interface is down

The interface given as source is down, so no source address can be chosen. Without source, every packet times out instead.

STEP 1 XE1 ping (without source)
XE1#ping 192.168.0.2 repeat 5 timeout 1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.2, timeout is 1 seconds:
.....
Success rate is 0 percent (0/5)

The reason is in the routing table. Shutting an interface down removes its connected routes from the routing table.

STEP 0 (before the shutdown) excerpt of XE1 show ip route
C        192.168.0.0/24 is directly connected, GigabitEthernet1
L        192.168.0.1/32 is directly connected, GigabitEthernet1

In STEP 1 these two lines are gone and there is no route to 192.168.0.0/24. Even though the IP address is still configured, the route is not used while the interface is down.

The Far-End Router Does Not Go Down

Even with XE1 shut down, XE2 on the far side stays up/up and logs nothing.

STEP 1 XE2 show ip interface brief (the far side)
XE2#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet1       192.168.0.2     YES TFTP   up                    up      
GigabitEthernet2       unassigned      YES unset  administratively down down    
GigabitEthernet3       unassigned      YES unset  administratively down down    
GigabitEthernet4       10.19.14.12     YES TFTP   up                    up      

On real hardware connected by fibre or copper, shutting one side down removes the carrier and the far end goes to up/down (Layer 1 up, Layer 2 down). In this verification environment (a virtual link in CML) it does not reach the far end. Traffic is stopped even though the far end still reads up/up, so do not conclude that the link is healthy from one side’s show output alone.

STEP 2: Bringing It Up Restores Everything

no shutdown brings it back.

STEP 2 XE1 applying no shutdown
XE1#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
XE1(config)#interface GigabitEthernet1
XE1(config-if)# no shutdown
XE1(config-if)#end

All fifty pings succeed again.

STEP 2 XE1 ping 192.168.0.2
XE1#ping 192.168.0.2 source GigabitEthernet1 repeat 50 timeout 1
Type escape sequence to abort.
Sending 50, 100-byte ICMP Echos to 192.168.0.2, timeout is 1 seconds:
Packet sent with a source address of 192.168.0.1 
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (50/50), round-trip min/avg/max = 2/2/4 ms
STEPGigabitEthernet1 on XE1Ping from XE1 to XE2
0up / up100% (50/50)
1administratively down / down0%
2up / up100% (50/50)

How It Looks in show running-config

shutdown and no shutdown are not symmetric in show running-config.

  • shutdown: a shutdown line appears in the interface configuration
  • no shutdown: no no shutdown line appears (it is the default, so it is not recorded as configuration)
Shut down (STEP 1)
XE1#show running-config interface GigabitEthernet1
Building configuration...

Current configuration : 137 bytes
!
interface GigabitEthernet1
 description to GigabitEthernet1.XE2
 ip address 192.168.0.1 255.255.255.0
 shutdown
 negotiation auto
end
Brought up (STEP 2)
XE1#show running-config interface GigabitEthernet1
Building configuration...

Current configuration : 127 bytes
!
interface GigabitEthernet1
 description to GigabitEthernet1.XE2
 ip address 192.168.0.1 255.255.255.0
 negotiation auto
end

To check whether an interface has been shut down unintentionally, look for a shutdown line in show running-config. If there is none, the interface is up.

Verification Configuration and show Output

The following kinds of output were collected from both routers at each step, in separate files per router. The verification configuration is the ..._run.txt file (the final state is the one from STEP 2).

FileContents
..._show.txtshow version / show interfaces description / show ip interface brief / show interfaces GigabitEthernet1 / show ip route / show arp / show running-config interface GigabitEthernet1
..._log.txtshow logging narrowed to that step. A marker is inserted with send log at the start of each step and the output is cut from there with | begin
..._run.txtshow running-config at that step (that is, the verification configuration)
..._ping.txtThe ping for that step (50 packets, 1-second timeout)
..._cfg.txtOnly the configuration applied in that step, produced by the device itself with show archive log config <range> provisioning

STEP 0: initial state

Routershow outputsyslogrunning-configpingapplied configuration
XE1showlogrunping-
XE2showlogrun--

STEP 1: shut down GigabitEthernet1 on XE1

Routershow outputsyslogrunning-configpingapplied configuration
XE1showlogrunping / without sourcecfg
XE2showlogrun--

STEP 2: bring GigabitEthernet1 on XE1 back up (final state)

Routershow outputsyslogrunning-configpingapplied configuration
XE1showlogrunpingcfg
XE2showlogrun--

The verification was performed on Catalyst 8000V (IOS XE 17.18.02) in Cisco Modeling Labs.

Related Articles

For configuring IP addresses see IOS XE Configuring an IPv4 Address on an Interface, and for saving the configuration see IOS XE Saving the Configuration.