How to find my IP address: local, private and public IP explained
How to find my IP address depends on which one you need. Your local IP sits on the network adapter: run ipconfig on Windows, ip addr on Linux or show ip interface brief on a switch. Your public IP is what internet servers see and can only be checked from outside. If they differ, NAT sits in between.
How to find my IP address starts with one question: which address do you mean? Your local IP is the address the operating system has configured on your network adapter, and one command on the machine shows it. Your public IP is the source address that servers on the internet see when you connect to them; the machine itself cannot show it, so you have to ask a service outside your network. At home, in an office or on a cloud server the two are usually different; on a data center server that has been given its own public IP they are the same. This guide covers the commands for Windows, Linux and network switches and how to read their output, explains why the two addresses differ and how to tell how many layers of NAT you are behind, and shows which address to pick when a machine lists several.
The short answer, depending on what you need:
| You want | Where it lives | How to find it |
|---|---|---|
| Local IP of a PC or server | On the network adapter | ipconfig on Windows, ip addr on Linux, ipconfig getifaddr en0 on macOS |
| IP of a switch | On a layer 3 interface such as a VLAN interface | show ip interface brief on Cisco, display ip interface brief on Huawei and H3C |
| Public IP | On your router, firewall or provider’s NAT device | Open any “what is my IP” site, or run curl -4 ifconfig.me |
How to find your IP address on Windows with ipconfig
Open Command Prompt (press Win + R and type cmd) or PowerShell:
ipconfig
ipconfig /all
ipconfig | findstr IPv4
ipconfig groups its output by adapter, each section starting with the adapter name. Find the adapter you are actually using; the three lines under it are the answer:
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::1c2b:3d4e:5f60:7182%12
IPv4 Address. . . . . . . . . . . : 192.168.1.23
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
| Field | Meaning |
|---|---|
| IPv4 Address | Your local IP, the address you are looking for |
| Subnet Mask | Together with the IP, defines which network the machine is on |
| Default Gateway | The next hop for other networks and the internet, normally your router or switch |
| Link-local IPv6 Address | Starts with fe80, generated automatically on every adapter and valid only on the local link |
ipconfig /all adds the details you need for troubleshooting. Physical Address is the adapter’s MAC. DHCP Enabled set to Yes means the address was obtained automatically, followed by the DHCP server and lease times. DNS Servers lists the resolvers in use. If you see Autoconfiguration IPv4 Address with a 169.254.x.x address, the adapter did not get an address from DHCP and assigned itself a temporary one. That address cannot reach the internet, so check the cable, the DHCP server or the switch port.
You can also find it without a command. In Windows 11, open Settings → Network & internet and click the active Ethernet or Wi-Fi connection; the IPv4 address appears in the connection’s properties, although the wording differs slightly between versions. Alternatively, open Control Panel → Network and Sharing Center, click the connection name and choose Details.
PowerShell has versions that are easier to use in scripts:
# All IPv4 addresses; PrefixOrigin Dhcp means obtained automatically, Manual means configured by hand
Get-NetIPAddress -AddressFamily IPv4 | Format-Table InterfaceAlias, IPAddress, PrefixLength, PrefixOrigin
# Only the adapter with a default gateway, normally the one actually used for internet traffic
Get-NetIPConfiguration | Where-Object IPv4DefaultGateway
How to find your IP address on Linux and macOS with ip addr
ip addr show # every address on every interface
ip -4 addr show # IPv4 only
ip -br -4 addr # one line per interface, quick to scan
hostname -I # just the addresses, without loopback
ip route show default # which interface the default route uses
Reading the ip addr output:
2: eno1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 52:54:00:12:34:56 brd ff:ff:ff:ff:ff:ff
inet 10.8.1.20/24 brd 10.8.1.255 scope global eno1
valid_lft forever preferred_lft forever
inet 10.8.1.21/24 brd 10.8.1.255 scope global secondary eno1
valid_lft forever preferred_lft forever
| Output | Meaning |
|---|---|
eno1 |
Interface name. eno1 is usually an onboard NIC, ens192 is common on VMware virtual machines, enp3s0 is named by PCI location, eth0 is the old naming scheme and bond0 is a bonded interface |
state UP, LOWER_UP |
The interface is enabled and the physical link is up; DOWN or NO-CARRIER means the cable is not connected or the interface is disabled |
link/ether 52:54:00:12:34:56 |
The interface’s MAC address |
inet 10.8.1.20/24 |
IPv4 address and prefix length; /24 is the mask 255.255.255.0 |
brd 10.8.1.255 |
The broadcast address of the subnet |
scope global |
An address usable for outside communication; loopback shows scope host |
secondary |
An additional address in the same subnet; the first one without secondary is the primary |
dynamic, valid_lft 86123sec |
Obtained by DHCP, followed by the remaining lease time; static addresses show forever |
ip -br is the brief output of newer iproute2 versions; on an old system that lacks it, use ip -4 addr show. ip route show default prints something like default via 10.8.1.1 dev eno1; the interface after dev is the one used to reach the outside world, and its address is normally the local IP you are after.
On macOS, ipconfig getifaddr en0 prints the address of a single interface directly. You can also open System Settings → Network and look at the details of the active connection.
How to find a switch’s IP address
Only layer 3 interfaces on a switch have IP addresses. A layer 2 access switch usually has a single management address on the management VLAN interface, while a layer 3 switch carries the gateway address of each subnet on its VLAN interfaces. Ordinary physical ports have no IP.
Cisco:
show ip interface brief
show ip interface brief | exclude unassigned
show ip interface Vlan99
Interface IP-Address OK? Method Status Protocol
Vlan1 unassigned YES unset administratively down down
Vlan99 10.8.3.13 YES manual up up
GigabitEthernet1/0/1 unassigned YES unset up up
The Cisco brief output does not include the mask. To see it, run show ip interface Vlan99, where the Internet address line reads like 10.8.3.13/27.
Huawei and H3C:
display ip interface brief
display ip interface brief | exclude unassigned
Sample output from a Huawei switch:
Interface IP Address/Mask Physical Protocol
MEth0/0/1 unassigned down down
NULL0 unassigned up up(s)
Vlanif10 10.8.10.1/24 up up
Vlanif99 10.8.3.11/27 up up
An address is only usable when both Physical and Protocol are up. MEth0/0/1 is the dedicated out-of-band management port on some models and shows unassigned when it has no address; adding | exclude unassigned hides every interface without an address. For the full details of a single interface, use display ip interface Vlanif99 on Huawei or display ip interface Vlan-interface99 on H3C.
Why your public IP is different from your local IP
A local IP only means something on the local network. Private ranges such as 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 are not routed on the internet, so before a packet can leave, a router or firewall rewrites its source address to a public one. This is NAT, and it can happen more than once:
Laptop 192.168.1.23 <- the local IP ipconfig shows
| home router NAT: source rewritten to the WAN address
Router WAN port 100.72.15.8
| carrier-grade NAT (CGNAT): rewritten again
Provider exit 203.0.113.45 <- "your IP" as websites see it
A NAT device tells connections apart by port number, so hundreds or thousands of devices can share one public address, and every one of them looks like the same IP to an outside website. That is also why your public IP can only be looked up from outside. One command does it: curl -4 ifconfig.me on Linux and macOS, or curl.exe -4 ifconfig.me on Windows. The -4 asks for the IPv4 address; without it, on a network with IPv6, you may get your IPv6 address instead.
To work out how many layers of NAT you are behind, compare three addresses:
| Local IP | Router WAN IP | Public IP you looked up | What it means |
|---|---|---|---|
| Public address | — | Same as the local IP | The machine holds a public address directly, like a data center server with its own IP |
| Private address | Public address | Same as the WAN IP | One layer of NAT; port forwarding on your router will work |
| Private address | Private, or starting 100.64 to 100.127 | Different from the WAN IP | Your provider adds another layer of NAT (CGNAT), so port forwarding on your own router has no effect |
| Private address (cloud server) | Not applicable | The public address the platform assigned | The cloud platform maps it one-to-one outside the VM; whether inbound traffic is allowed depends on the security group |
The difference matters in practice. When someone needs to allowlist your server, give them the public IP, not the address from ipconfig. Logs on outside systems record the public IP, so search for that when troubleshooting. And everyone in one office shares the same public IP, so a service that rate-limits by IP treats the whole office as one user.
Several IP addresses listed: which one is yours?
On a machine with virtual machines, Docker or a VPN, ipconfig or ip addr prints a long list, and most of it is not what you want:
| Address or adapter | What it is | Your local IP? |
|---|---|---|
| 127.0.0.1 (lo) | Loopback | No, used only inside the machine |
| 169.254.x.x | Self-assigned after DHCP failed | No, this adapter did not get a proper address |
| 172.17.0.1 on docker0 | Docker’s default bridge | No, it is the gateway of the container network |
| 192.168.122.1 on virbr0 | The default KVM/libvirt NAT network | No |
| VMware Network Adapter VMnet1 or VMnet8, vEthernet (WSL) | Virtual adapters for VMs and WSL | No |
| VPN or mesh networking adapters, such as an address in 100.64.0.0/10 | Address inside the virtual private network | Only meaningful inside the VPN |
| Several inet lines on one interface, marked secondary | Additional server IPs | All are local IPs; the one without secondary is primary |
| The address on the adapter with the default gateway or default route | The interface actually used for internet traffic | Normally the one you want |
There is one rule: start from the adapter that has the default gateway. On Windows, that is the ipconfig section where Default Gateway is not empty; on Linux, it is the interface named after dev in ip route show default.
Finding a server’s IP in a data center without logging in
When a customer reports a fault, a server password is lost or you are auditing records, you often need a server’s address without logging in to it:
- Check the IP records. If the address was recorded when it was assigned, look it up by server or rack position. This is the fastest way.
- Trace it from the switch. On the access switch, find the MAC learned on the server’s port (
show mac address-table interface GigabitEthernet1/0/5on Cisco,display mac-address GigabitEthernet0/0/5on Huawei,display mac-address interface GigabitEthernet1/0/5on H3C). Then look the MAC up in the gateway’s ARP table:show ip arp | include 5254.0012.3456on Cisco,display arp | include 5254-0012-3456on Huawei and H3C. The matching IP is the address the server is using right now. - Find the BMC management address. If you can get into the OS,
ipmitool lan print 1shows the BMC’s IP Address, Subnet Mask and MAC Address; the channel is 1 on most models but differs on a few. If you cannot get into the OS, the address is also shown on the POST screen or in the IPMI/BMC page of the BIOS setup.
Method 2 gives the address actually in use. If it does not match the records, someone changed the IP or the records were never updated. In Toplink DCIM, IP address management records which server every address is assigned to and which block it belongs to, and IPMI address blocks can be typed separately and counted on their own. Switch management shows which switch and port each server is connected to in the server list, and can apply ARP binding and source guard on the switch, so if a customer changes their IP without permission, the traffic is dropped at the port and the records never drift far from reality.
FAQ
Linux says ifconfig: command not found. What now?
Newer Debian, Ubuntu and RHEL-family releases no longer install net-tools by default, so use ip addr instead, or install the net-tools package if you really want ifconfig. Be aware that ifconfig does not show extra addresses added with ip addr add without a label, so on servers with several IPs, trust the ip addr output.
Why does my IP address change every time I restart?
The address is assigned by DHCP, so it can change when the lease expires or the network adapter is replaced. To keep it fixed, either reserve the address for your MAC on the router or DHCP server, or configure a static IP on the machine itself; pick a static address outside the DHCP pool so it never clashes with another device.
Where do I find the IP address on my phone?
On Android, open the Wi-Fi settings and tap the connected network to see its details; menu names vary by manufacturer. On an iPhone, go to Settings → Wi-Fi and tap the info button next to the connected network. That is the phone's address on the Wi-Fi network; its public IP still has to be looked up from an outside website.