Powershell Cheat Sheet for Network Engineers

PowerShell Network Engineer / Architect Cheat Sheet

Networking-focused PowerShell and Windows commands for troubleshooting IP addressing, routing, DNS, TCP/UDP connectivity, interfaces, ARP, firewalls, MTU, and application connectivity.

1. IP Address / Interface

Task Command
Show IP configuration Get-NetIPConfiguration
Detailed IP configuration Get-NetIPConfiguration -Detailed
Show IP addresses Get-NetIPAddress
IPv4 addresses only Get-NetIPAddress -AddressFamily IPv4
Show network adapters Get-NetAdapter
Active adapters only Get-NetAdapter | Where-Object Status -eq "Up"
Interface statistics Get-NetAdapterStatistics
IP interface information Get-NetIPInterface
IPv4 interfaces Get-NetIPInterface -AddressFamily IPv4
Configured DNS servers Get-DnsClientServerAddress
DNS servers for Ethernet Get-DnsClientServerAddress -InterfaceAlias "Ethernet"
MAC address / speed / status Get-NetAdapter | Select Name,MacAddress,LinkSpeed,Status

Detailed Interface View

Get-NetIPConfiguration | Format-List *

2. Routing Table

Task Command
Show routing table Get-NetRoute
IPv4 routes only Get-NetRoute -AddressFamily IPv4
Sort by destination prefix Get-NetRoute -AddressFamily IPv4 | Sort-Object DestinationPrefix
Show default route Get-NetRoute -DestinationPrefix "0.0.0.0/0"
Show route metrics Get-NetRoute | Select DestinationPrefix,NextHop,RouteMetric,InterfaceAlias
Routes for interface Get-NetRoute -InterfaceAlias "Ethernet"
Traditional route table route print
IPv4 routing table route print -4

Clean IPv4 Routing View

Get-NetRoute -AddressFamily IPv4 |
Sort-Object DestinationPrefix |
Format-Table DestinationPrefix,NextHop,InterfaceAlias,RouteMetric -AutoSize

Default Route

Get-NetRoute -DestinationPrefix "0.0.0.0/0" |
Format-Table DestinationPrefix,NextHop,InterfaceAlias,RouteMetric

3. Route Lookup

Determine which route, interface, next hop, and source IP Windows will use to reach a destination.

Find-NetRoute -RemoteIPAddress 8.8.8.8

Enterprise example:

Find-NetRoute -RemoteIPAddress 10.192.20.50
Very useful: This is one of the best commands for answering “Which route will Windows actually use?”

4. Connectivity Testing

Task Command
Basic connectivity test Test-NetConnection 8.8.8.8
Short alias tnc 8.8.8.8
Test TCP 443 Test-NetConnection server.example.com -Port 443
Detailed TCP test Test-NetConnection server.example.com -Port 443 -InformationLevel Detailed

Important output fields:

RemoteAddress
RemotePort
InterfaceAlias
SourceAddress
TcpTestSucceeded

5. Ping

Task Command
Basic ping ping 8.8.8.8
Continuous ping ping -t 8.8.8.8
Send 20 pings ping -n 20 8.8.8.8
Attempt reverse name resolution ping -a 10.1.1.10

6. Traceroute / Path Testing

Task Command
PowerShell traceroute Test-NetConnection 8.8.8.8 -TraceRoute
Traditional traceroute tracert 8.8.8.8
Traceroute without DNS lookups tracert -d 8.8.8.8
Traceroute + packet loss statistics pathping 8.8.8.8
Tip: Use tracert -d when troubleshooting routing. It avoids DNS lookup delays for every hop.

7. DNS Resolution

Task Command
Basic DNS lookup Resolve-DnsName example.com
A record Resolve-DnsName example.com -Type A
AAAA record Resolve-DnsName example.com -Type AAAA
CNAME record Resolve-DnsName example.com -Type CNAME
MX record Resolve-DnsName example.com -Type MX
TXT record Resolve-DnsName example.com -Type TXT
NS record Resolve-DnsName example.com -Type NS
Reverse DNS lookup Resolve-DnsName 8.8.8.8
Query Google DNS Resolve-DnsName example.com -Server 8.8.8.8
Query specific internal DNS server Resolve-DnsName server.company.com -Server 10.10.10.10

8. Compare DNS Servers

Resolve-DnsName example.com -Server 8.8.8.8
Resolve-DnsName example.com -Server 1.1.1.1

Multiple DNS servers:

"8.8.8.8","1.1.1.1" | ForEach-Object {
    Resolve-DnsName example.com -Server $_
}

Useful for troubleshooting:

  • Split DNS
  • DNS propagation
  • Stale records
  • Cloud endpoints
  • Load balancers
  • Proxy and application routing

9. DNS Cache

Task Command
Show DNS cache Get-DnsClientCache
Search DNS cache Get-DnsClientCache | Where-Object Entry -like "*amazon*"
Clear DNS cache Clear-DnsClientCache
Classic flush ipconfig /flushdns

10. ARP / Neighbor Table

Task Command
Show neighbors Get-NetNeighbor
IPv4 neighbors Get-NetNeighbor -AddressFamily IPv4
Specific IP Get-NetNeighbor -IPAddress 10.1.1.1
Traditional ARP table arp -a

Formatted Neighbor Table

Get-NetNeighbor -AddressFamily IPv4 |
Format-Table IPAddress,LinkLayerAddress,State,InterfaceAlias

11. TCP Connections

Task Command
All TCP connections Get-NetTCPConnection
Established connections Get-NetTCPConnection -State Established
Listening ports Get-NetTCPConnection -State Listen
Connections using remote TCP 443 Get-NetTCPConnection -RemotePort 443
Specific remote destination Get-NetTCPConnection | Where-Object RemoteAddress -eq "10.10.10.10"

Clean TCP View

Get-NetTCPConnection |
Select LocalAddress,LocalPort,RemoteAddress,RemotePort,State

12. Find the Process Using a TCP Connection

Get-NetTCPConnection |
Select LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess

Then identify the process:

Get-Process -Id 1234

Combined View

Get-NetTCPConnection -State Established |
Select LocalAddress,
       LocalPort,
       RemoteAddress,
       RemotePort,
       @{Name="Process";Expression={(Get-Process -Id $_.OwningProcess).ProcessName}}

13. Netstat

Task Command
Connections + PID netstat -ano
Active connections netstat -an
Listening connections netstat -ano | findstr LISTENING
TCP 443 netstat -ano | findstr :443
Specific destination netstat -ano | findstr 10.10.10.10

14. UDP

Get-NetUDPEndpoint

Formatted UDP View

Get-NetUDPEndpoint |
Format-Table LocalAddress,LocalPort,OwningProcess

15. TCP Port Testing

Useful when ICMP is blocked.

Test-NetConnection hostname -Port 443

Common examples:

tnc server.company.com -Port 22
tnc server.company.com -Port 53
tnc server.company.com -Port 443
tnc server.company.com -Port 3389
Important: Test-NetConnection -Port tests TCP. It does not perform a UDP port test.

16. Source IP / Interface Selection

Test-NetConnection example.com -Port 443 -InformationLevel Detailed

Look for:

InterfaceAlias
SourceAddress
NetRoute

Particularly useful on hosts with multiple NICs, VPN clients, Wi-Fi, Ethernet, management networks, or cloud interfaces.

17. Public / NAT IP

Invoke-RestMethod https://api.ipify.org

Alternative:

Invoke-RestMethod https://ifconfig.me/ip

Useful for determining the public NAT or Internet egress address of a host.

18. HTTP / HTTPS Testing

Invoke-WebRequest https://example.com

Alias:

iwr https://example.com

Display Response Information

Invoke-WebRequest https://example.com |
Select StatusCode,StatusDescription,Headers

19. HTTP Response Timing

Measure-Command {
    Invoke-WebRequest https://example.com
}

Look for:

TotalMilliseconds

20. TLS Certificate Inspection

$tcp = New-Object Net.Sockets.TcpClient("example.com",443)

$ssl = New-Object Net.Security.SslStream(
    $tcp.GetStream(),
    $false
)

$ssl.AuthenticateAsClient("example.com")

$ssl.RemoteCertificate

21. Windows Firewall

Task Command
Firewall profiles Get-NetFirewallProfile
All firewall rules Get-NetFirewallRule
Enabled rules Get-NetFirewallRule | Where-Object Enabled -eq "True"
Search rules Get-NetFirewallRule | Where-Object DisplayName -like "*SSH*"
Port filters Get-NetFirewallPortFilter

22. Interface Metric

Get-NetIPInterface -AddressFamily IPv4 |
Sort-Object InterfaceMetric

Useful when troubleshooting unexpected interface or route selection.

23. DHCP / IP Configuration

Task Command
IP configuration Get-NetIPConfiguration
Interface configuration Get-NetIPInterface
Traditional detailed configuration ipconfig /all
Release DHCP address ipconfig /release
Renew DHCP address ipconfig /renew

24. Network Profiles

Get-NetConnectionProfile

Shows information such as:

InterfaceAlias
NetworkCategory
IPv4Connectivity
IPv6Connectivity

25. Adapter Details

Get-NetAdapter |
Format-Table Name,InterfaceDescription,Status,LinkSpeed,MacAddress

Advanced NIC Properties

Get-NetAdapterAdvancedProperty

Specific interface:

Get-NetAdapterAdvancedProperty -Name "Ethernet"

26. MTU Troubleshooting

Display MTU

Get-NetIPInterface |
Select InterfaceAlias,AddressFamily,NlMtu

Traditional:

netsh interface ipv4 show subinterfaces

Test MTU / Fragmentation

ping 8.8.8.8 -f -l 1472

Standard Ethernet calculation:

1472 byte ICMP payload
+ 20 byte IPv4 header
+ 8 byte ICMP header
---------------------
= 1500 byte MTU

27. Useful PowerShell Filters

Find Routes Through a Next Hop

Get-NetRoute |
Where-Object NextHop -eq "10.1.1.1"

Search DNS Cache

Get-DnsClientCache |
Where-Object Entry -like "*aws*"

Find Connections to a Subnet

Get-NetTCPConnection |
Where-Object RemoteAddress -like "10.192.*"

Find TCP 443 Connections

Get-NetTCPConnection |
Where-Object RemotePort -eq 443

28. Network Engineer Top Commands

# ------------------------------------------------------
# IP / INTERFACES
# ------------------------------------------------------

Get-NetIPConfiguration
Get-NetIPAddress -AddressFamily IPv4
Get-NetAdapter
Get-NetIPInterface -AddressFamily IPv4


# ------------------------------------------------------
# ROUTING
# ------------------------------------------------------

Get-NetRoute -AddressFamily IPv4
Get-NetRoute -DestinationPrefix "0.0.0.0/0"

Find-NetRoute -RemoteIPAddress 10.10.10.10

route print -4


# ------------------------------------------------------
# CONNECTIVITY
# ------------------------------------------------------

ping 10.10.10.10

tracert -d 10.10.10.10

Test-NetConnection 10.10.10.10

Test-NetConnection server.company.com -Port 443


# ------------------------------------------------------
# DNS
# ------------------------------------------------------

Resolve-DnsName server.company.com

Resolve-DnsName server.company.com -Type A

Resolve-DnsName server.company.com -Server 8.8.8.8

Get-DnsClientServerAddress

Get-DnsClientCache

Clear-DnsClientCache


# ------------------------------------------------------
# ARP / NEIGHBOR
# ------------------------------------------------------

Get-NetNeighbor -AddressFamily IPv4

arp -a


# ------------------------------------------------------
# TCP
# ------------------------------------------------------

Get-NetTCPConnection

Get-NetTCPConnection -State Established

Get-NetTCPConnection -State Listen

netstat -ano


# ------------------------------------------------------
# WINDOWS FIREWALL
# ------------------------------------------------------

Get-NetFirewallProfile

Get-NetFirewallRule


# ------------------------------------------------------
# MTU
# ------------------------------------------------------

Get-NetIPInterface |
Select InterfaceAlias,AddressFamily,NlMtu

ping 8.8.8.8 -f -l 1472

29. Five High-Value Troubleshooting Commands

Which Route Will Windows Use?

Find-NetRoute -RemoteIPAddress 10.192.10.50

Can I Establish TCP Connectivity?

Test-NetConnection hostname -Port 443 -InformationLevel Detailed

What Does a Specific DNS Server Return?

Resolve-DnsName hostname -Server DNS-SERVER-IP

What TCP Sessions Exist?

Get-NetTCPConnection -State Established

What is the Host’s Complete Layer-3 Configuration?

Get-NetIPConfiguration -Detailed

30. Basic Network Troubleshooting Workflow

# 1. Check local IP configuration
Get-NetIPConfiguration -Detailed

# 2. Check the route Windows will use
Find-NetRoute -RemoteIPAddress 10.10.10.10

# 3. Check DNS
Resolve-DnsName server.company.com

# 4. Test basic reachability
ping 10.10.10.10

# 5. Check the network path
tracert -d 10.10.10.10

# 6. Test the actual application port
Test-NetConnection server.company.com -Port 443 -InformationLevel Detailed

# 7. Check existing TCP sessions
Get-NetTCPConnection -State Established

# 8. Check ARP / neighbor resolution
Get-NetNeighbor -AddressFamily IPv4