Networking & IP

How to find my IP address: local, private and public IP explained

How to find my IP address depends on which one you need. Your local IP sits on the network adapter: run ipconfig on Windows, ip addr on Linux or show ip interface brief on a switch. Your public IP is what internet servers see and can only be checked from outside. If they differ, NAT sits in between.

By Toplink product teamPublished 10 min read

How to find my IP address starts with one question: which address do you mean? Your local IP is the address the operating system has configured on your network adapter, and one command on the machine shows it. Your public IP is the source address that servers on the internet see when you connect to them; the machine itself cannot show it, so you have to ask a service outside your network. At home, in an office or on a cloud server the two are usually different; on a data center server that has been given its own public IP they are the same. This guide covers the commands for Windows, Linux and network switches and how to read their output, explains why the two addresses differ and how to tell how many layers of NAT you are behind, and shows which address to pick when a machine lists several.

The short answer, depending on what you need:

You want Where it lives How to find it
Local IP of a PC or server On the network adapter ipconfig on Windows, ip addr on Linux, ipconfig getifaddr en0 on macOS
IP of a switch On a layer 3 interface such as a VLAN interface show ip interface brief on Cisco, display ip interface brief on Huawei and H3C
Public IP On your router, firewall or provider’s NAT device Open any “what is my IP” site, or run curl -4 ifconfig.me

How to find your IP address on Windows with ipconfig

Open Command Prompt (press Win + R and type cmd) or PowerShell:

ipconfig
ipconfig /all
ipconfig | findstr IPv4

ipconfig groups its output by adapter, each section starting with the adapter name. Find the adapter you are actually using; the three lines under it are the answer:

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::1c2b:3d4e:5f60:7182%12
   IPv4 Address. . . . . . . . . . . : 192.168.1.23
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
Field Meaning
IPv4 Address Your local IP, the address you are looking for
Subnet Mask Together with the IP, defines which network the machine is on
Default Gateway The next hop for other networks and the internet, normally your router or switch
Link-local IPv6 Address Starts with fe80, generated automatically on every adapter and valid only on the local link

ipconfig /all adds the details you need for troubleshooting. Physical Address is the adapter’s MAC. DHCP Enabled set to Yes means the address was obtained automatically, followed by the DHCP server and lease times. DNS Servers lists the resolvers in use. If you see Autoconfiguration IPv4 Address with a 169.254.x.x address, the adapter did not get an address from DHCP and assigned itself a temporary one. That address cannot reach the internet, so check the cable, the DHCP server or the switch port.

You can also find it without a command. In Windows 11, open Settings → Network & internet and click the active Ethernet or Wi-Fi connection; the IPv4 address appears in the connection’s properties, although the wording differs slightly between versions. Alternatively, open Control Panel → Network and Sharing Center, click the connection name and choose Details.

PowerShell has versions that are easier to use in scripts:

# All IPv4 addresses; PrefixOrigin Dhcp means obtained automatically, Manual means configured by hand
Get-NetIPAddress -AddressFamily IPv4 | Format-Table InterfaceAlias, IPAddress, PrefixLength, PrefixOrigin

# Only the adapter with a default gateway, normally the one actually used for internet traffic
Get-NetIPConfiguration | Where-Object IPv4DefaultGateway

How to find your IP address on Linux and macOS with ip addr

ip addr show            # every address on every interface
ip -4 addr show         # IPv4 only
ip -br -4 addr          # one line per interface, quick to scan
hostname -I             # just the addresses, without loopback
ip route show default   # which interface the default route uses

Reading the ip addr output:

2: eno1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 52:54:00:12:34:56 brd ff:ff:ff:ff:ff:ff
    inet 10.8.1.20/24 brd 10.8.1.255 scope global eno1
       valid_lft forever preferred_lft forever
    inet 10.8.1.21/24 brd 10.8.1.255 scope global secondary eno1
       valid_lft forever preferred_lft forever
Output Meaning
eno1 Interface name. eno1 is usually an onboard NIC, ens192 is common on VMware virtual machines, enp3s0 is named by PCI location, eth0 is the old naming scheme and bond0 is a bonded interface
state UP, LOWER_UP The interface is enabled and the physical link is up; DOWN or NO-CARRIER means the cable is not connected or the interface is disabled
link/ether 52:54:00:12:34:56 The interface’s MAC address
inet 10.8.1.20/24 IPv4 address and prefix length; /24 is the mask 255.255.255.0
brd 10.8.1.255 The broadcast address of the subnet
scope global An address usable for outside communication; loopback shows scope host
secondary An additional address in the same subnet; the first one without secondary is the primary
dynamic, valid_lft 86123sec Obtained by DHCP, followed by the remaining lease time; static addresses show forever

ip -br is the brief output of newer iproute2 versions; on an old system that lacks it, use ip -4 addr show. ip route show default prints something like default via 10.8.1.1 dev eno1; the interface after dev is the one used to reach the outside world, and its address is normally the local IP you are after.

On macOS, ipconfig getifaddr en0 prints the address of a single interface directly. You can also open System Settings → Network and look at the details of the active connection.

How to find a switch’s IP address

Only layer 3 interfaces on a switch have IP addresses. A layer 2 access switch usually has a single management address on the management VLAN interface, while a layer 3 switch carries the gateway address of each subnet on its VLAN interfaces. Ordinary physical ports have no IP.

Cisco:

show ip interface brief
show ip interface brief | exclude unassigned
show ip interface Vlan99
Interface              IP-Address      OK? Method Status                Protocol
Vlan1                  unassigned      YES unset  administratively down down
Vlan99                 10.8.3.13       YES manual up                    up
GigabitEthernet1/0/1   unassigned      YES unset  up                    up

The Cisco brief output does not include the mask. To see it, run show ip interface Vlan99, where the Internet address line reads like 10.8.3.13/27.

Huawei and H3C:

display ip interface brief
display ip interface brief | exclude unassigned

Sample output from a Huawei switch:

Interface                         IP Address/Mask      Physical   Protocol
MEth0/0/1                         unassigned           down       down
NULL0                             unassigned           up         up(s)
Vlanif10                          10.8.10.1/24         up         up
Vlanif99                          10.8.3.11/27         up         up

An address is only usable when both Physical and Protocol are up. MEth0/0/1 is the dedicated out-of-band management port on some models and shows unassigned when it has no address; adding | exclude unassigned hides every interface without an address. For the full details of a single interface, use display ip interface Vlanif99 on Huawei or display ip interface Vlan-interface99 on H3C.

Why your public IP is different from your local IP

A local IP only means something on the local network. Private ranges such as 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 are not routed on the internet, so before a packet can leave, a router or firewall rewrites its source address to a public one. This is NAT, and it can happen more than once:

Laptop             192.168.1.23     <- the local IP ipconfig shows
   |  home router NAT: source rewritten to the WAN address
Router WAN port    100.72.15.8
   |  carrier-grade NAT (CGNAT): rewritten again
Provider exit      203.0.113.45     <- "your IP" as websites see it

A NAT device tells connections apart by port number, so hundreds or thousands of devices can share one public address, and every one of them looks like the same IP to an outside website. That is also why your public IP can only be looked up from outside. One command does it: curl -4 ifconfig.me on Linux and macOS, or curl.exe -4 ifconfig.me on Windows. The -4 asks for the IPv4 address; without it, on a network with IPv6, you may get your IPv6 address instead.

To work out how many layers of NAT you are behind, compare three addresses:

Local IP Router WAN IP Public IP you looked up What it means
Public address — Same as the local IP The machine holds a public address directly, like a data center server with its own IP
Private address Public address Same as the WAN IP One layer of NAT; port forwarding on your router will work
Private address Private, or starting 100.64 to 100.127 Different from the WAN IP Your provider adds another layer of NAT (CGNAT), so port forwarding on your own router has no effect
Private address (cloud server) Not applicable The public address the platform assigned The cloud platform maps it one-to-one outside the VM; whether inbound traffic is allowed depends on the security group

The difference matters in practice. When someone needs to allowlist your server, give them the public IP, not the address from ipconfig. Logs on outside systems record the public IP, so search for that when troubleshooting. And everyone in one office shares the same public IP, so a service that rate-limits by IP treats the whole office as one user.

Several IP addresses listed: which one is yours?

On a machine with virtual machines, Docker or a VPN, ipconfig or ip addr prints a long list, and most of it is not what you want:

Address or adapter What it is Your local IP?
127.0.0.1 (lo) Loopback No, used only inside the machine
169.254.x.x Self-assigned after DHCP failed No, this adapter did not get a proper address
172.17.0.1 on docker0 Docker’s default bridge No, it is the gateway of the container network
192.168.122.1 on virbr0 The default KVM/libvirt NAT network No
VMware Network Adapter VMnet1 or VMnet8, vEthernet (WSL) Virtual adapters for VMs and WSL No
VPN or mesh networking adapters, such as an address in 100.64.0.0/10 Address inside the virtual private network Only meaningful inside the VPN
Several inet lines on one interface, marked secondary Additional server IPs All are local IPs; the one without secondary is primary
The address on the adapter with the default gateway or default route The interface actually used for internet traffic Normally the one you want

There is one rule: start from the adapter that has the default gateway. On Windows, that is the ipconfig section where Default Gateway is not empty; on Linux, it is the interface named after dev in ip route show default.

Finding a server’s IP in a data center without logging in

When a customer reports a fault, a server password is lost or you are auditing records, you often need a server’s address without logging in to it:

  1. Check the IP records. If the address was recorded when it was assigned, look it up by server or rack position. This is the fastest way.
  2. Trace it from the switch. On the access switch, find the MAC learned on the server’s port (show mac address-table interface GigabitEthernet1/0/5 on Cisco, display mac-address GigabitEthernet0/0/5 on Huawei, display mac-address interface GigabitEthernet1/0/5 on H3C). Then look the MAC up in the gateway’s ARP table: show ip arp | include 5254.0012.3456 on Cisco, display arp | include 5254-0012-3456 on Huawei and H3C. The matching IP is the address the server is using right now.
  3. Find the BMC management address. If you can get into the OS, ipmitool lan print 1 shows the BMC’s IP Address, Subnet Mask and MAC Address; the channel is 1 on most models but differs on a few. If you cannot get into the OS, the address is also shown on the POST screen or in the IPMI/BMC page of the BIOS setup.

Method 2 gives the address actually in use. If it does not match the records, someone changed the IP or the records were never updated. In Toplink DCIM, IP address management records which server every address is assigned to and which block it belongs to, and IPMI address blocks can be typed separately and counted on their own. Switch management shows which switch and port each server is connected to in the server list, and can apply ARP binding and source guard on the switch, so if a customer changes their IP without permission, the traffic is dropped at the port and the records never drift far from reality.

FAQ

Linux says ifconfig: command not found. What now?

Newer Debian, Ubuntu and RHEL-family releases no longer install net-tools by default, so use ip addr instead, or install the net-tools package if you really want ifconfig. Be aware that ifconfig does not show extra addresses added with ip addr add without a label, so on servers with several IPs, trust the ip addr output.

Why does my IP address change every time I restart?

The address is assigned by DHCP, so it can change when the lease expires or the network adapter is replaced. To keep it fixed, either reserve the address for your MAC on the router or DHCP server, or configure a static IP on the machine itself; pick a static address outside the DHCP pool so it never clashes with another device.

Where do I find the IP address on my phone?

On Android, open the Wi-Fi settings and tap the connected network to see its details; menu names vary by manufacturer. On an iPhone, go to Settings → Wi-Fi and tap the info button next to the connected network. That is the phone's address on the Wi-Fi network; its public IP still has to be looked up from an outside website.

See how it works in your data center.

Start with a product demo and map out your next step.

View pricing
Hotline 400-112-2951

Let’s talk about your IDC

Scan with WeChat to book a product demo or request a trial.

Toplink WeCom contact QR code

Save this code or scan it with WeChat / WeCom

Or call
400-112-2951
Telegram
@TopLink88