PowerShell Network Engineer / Architect Cheat Sheet
Networking-focused PowerShell and Windows commands for troubleshooting IP addressing, routing, DNS, TCP/UDP connectivity, interfaces, ARP, firewalls, MTU, and application connectivity.
1. IP Address / Interface
| Task | Command |
|---|---|
| Show IP configuration | Get-NetIPConfiguration |
| Detailed IP configuration | Get-NetIPConfiguration -Detailed |
| Show IP addresses | Get-NetIPAddress |
| IPv4 addresses only | Get-NetIPAddress -AddressFamily IPv4 |
| Show network adapters | Get-NetAdapter |
| Active adapters only | Get-NetAdapter | Where-Object Status -eq "Up" |
| Interface statistics | Get-NetAdapterStatistics |
| IP interface information | Get-NetIPInterface |
| IPv4 interfaces | Get-NetIPInterface -AddressFamily IPv4 |
| Configured DNS servers | Get-DnsClientServerAddress |
| DNS servers for Ethernet | Get-DnsClientServerAddress -InterfaceAlias "Ethernet" |
| MAC address / speed / status | Get-NetAdapter | Select Name,MacAddress,LinkSpeed,Status |
Detailed Interface View
Get-NetIPConfiguration | Format-List *
2. Routing Table
| Task | Command |
|---|---|
| Show routing table | Get-NetRoute |
| IPv4 routes only | Get-NetRoute -AddressFamily IPv4 |
| Sort by destination prefix | Get-NetRoute -AddressFamily IPv4 | Sort-Object DestinationPrefix |
| Show default route | Get-NetRoute -DestinationPrefix "0.0.0.0/0" |
| Show route metrics | Get-NetRoute | Select DestinationPrefix,NextHop,RouteMetric,InterfaceAlias |
| Routes for interface | Get-NetRoute -InterfaceAlias "Ethernet" |
| Traditional route table | route print |
| IPv4 routing table | route print -4 |
Clean IPv4 Routing View
Get-NetRoute -AddressFamily IPv4 | Sort-Object DestinationPrefix | Format-Table DestinationPrefix,NextHop,InterfaceAlias,RouteMetric -AutoSize
Default Route
Get-NetRoute -DestinationPrefix "0.0.0.0/0" | Format-Table DestinationPrefix,NextHop,InterfaceAlias,RouteMetric
3. Route Lookup
Determine which route, interface, next hop, and source IP Windows will use to reach a destination.
Find-NetRoute -RemoteIPAddress 8.8.8.8
Enterprise example:
Find-NetRoute -RemoteIPAddress 10.192.20.50
4. Connectivity Testing
| Task | Command |
|---|---|
| Basic connectivity test | Test-NetConnection 8.8.8.8 |
| Short alias | tnc 8.8.8.8 |
| Test TCP 443 | Test-NetConnection server.example.com -Port 443 |
| Detailed TCP test | Test-NetConnection server.example.com -Port 443 -InformationLevel Detailed |
Important output fields:
RemoteAddress RemotePort InterfaceAlias SourceAddress TcpTestSucceeded
5. Ping
| Task | Command |
|---|---|
| Basic ping | ping 8.8.8.8 |
| Continuous ping | ping -t 8.8.8.8 |
| Send 20 pings | ping -n 20 8.8.8.8 |
| Attempt reverse name resolution | ping -a 10.1.1.10 |
6. Traceroute / Path Testing
| Task | Command |
|---|---|
| PowerShell traceroute | Test-NetConnection 8.8.8.8 -TraceRoute |
| Traditional traceroute | tracert 8.8.8.8 |
| Traceroute without DNS lookups | tracert -d 8.8.8.8 |
| Traceroute + packet loss statistics | pathping 8.8.8.8 |
tracert -d when troubleshooting routing. It avoids DNS lookup delays for every hop.7. DNS Resolution
| Task | Command |
|---|---|
| Basic DNS lookup | Resolve-DnsName example.com |
| A record | Resolve-DnsName example.com -Type A |
| AAAA record | Resolve-DnsName example.com -Type AAAA |
| CNAME record | Resolve-DnsName example.com -Type CNAME |
| MX record | Resolve-DnsName example.com -Type MX |
| TXT record | Resolve-DnsName example.com -Type TXT |
| NS record | Resolve-DnsName example.com -Type NS |
| Reverse DNS lookup | Resolve-DnsName 8.8.8.8 |
| Query Google DNS | Resolve-DnsName example.com -Server 8.8.8.8 |
| Query specific internal DNS server | Resolve-DnsName server.company.com -Server 10.10.10.10 |
8. Compare DNS Servers
Resolve-DnsName example.com -Server 8.8.8.8 Resolve-DnsName example.com -Server 1.1.1.1
Multiple DNS servers:
"8.8.8.8","1.1.1.1" | ForEach-Object {
Resolve-DnsName example.com -Server $_
}
Useful for troubleshooting:
- Split DNS
- DNS propagation
- Stale records
- Cloud endpoints
- Load balancers
- Proxy and application routing
9. DNS Cache
| Task | Command |
|---|---|
| Show DNS cache | Get-DnsClientCache |
| Search DNS cache | Get-DnsClientCache | Where-Object Entry -like "*amazon*" |
| Clear DNS cache | Clear-DnsClientCache |
| Classic flush | ipconfig /flushdns |
10. ARP / Neighbor Table
| Task | Command |
|---|---|
| Show neighbors | Get-NetNeighbor |
| IPv4 neighbors | Get-NetNeighbor -AddressFamily IPv4 |
| Specific IP | Get-NetNeighbor -IPAddress 10.1.1.1 |
| Traditional ARP table | arp -a |
Formatted Neighbor Table
Get-NetNeighbor -AddressFamily IPv4 | Format-Table IPAddress,LinkLayerAddress,State,InterfaceAlias
11. TCP Connections
| Task | Command |
|---|---|
| All TCP connections | Get-NetTCPConnection |
| Established connections | Get-NetTCPConnection -State Established |
| Listening ports | Get-NetTCPConnection -State Listen |
| Connections using remote TCP 443 | Get-NetTCPConnection -RemotePort 443 |
| Specific remote destination | Get-NetTCPConnection | Where-Object RemoteAddress -eq "10.10.10.10" |
Clean TCP View
Get-NetTCPConnection | Select LocalAddress,LocalPort,RemoteAddress,RemotePort,State
12. Find the Process Using a TCP Connection
Get-NetTCPConnection | Select LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess
Then identify the process:
Get-Process -Id 1234
Combined View
Get-NetTCPConnection -State Established |
Select LocalAddress,
LocalPort,
RemoteAddress,
RemotePort,
@{Name="Process";Expression={(Get-Process -Id $_.OwningProcess).ProcessName}}
13. Netstat
| Task | Command |
|---|---|
| Connections + PID | netstat -ano |
| Active connections | netstat -an |
| Listening connections | netstat -ano | findstr LISTENING |
| TCP 443 | netstat -ano | findstr :443 |
| Specific destination | netstat -ano | findstr 10.10.10.10 |
14. UDP
Get-NetUDPEndpoint
Formatted UDP View
Get-NetUDPEndpoint | Format-Table LocalAddress,LocalPort,OwningProcess
15. TCP Port Testing
Useful when ICMP is blocked.
Test-NetConnection hostname -Port 443
Common examples:
tnc server.company.com -Port 22 tnc server.company.com -Port 53 tnc server.company.com -Port 443 tnc server.company.com -Port 3389
Test-NetConnection -Port tests TCP. It does not perform a UDP port test.16. Source IP / Interface Selection
Test-NetConnection example.com -Port 443 -InformationLevel Detailed
Look for:
InterfaceAlias SourceAddress NetRoute
Particularly useful on hosts with multiple NICs, VPN clients, Wi-Fi, Ethernet, management networks, or cloud interfaces.
17. Public / NAT IP
Invoke-RestMethod https://api.ipify.org
Alternative:
Invoke-RestMethod https://ifconfig.me/ip
Useful for determining the public NAT or Internet egress address of a host.
18. HTTP / HTTPS Testing
Invoke-WebRequest https://example.com
Alias:
iwr https://example.com
Display Response Information
Invoke-WebRequest https://example.com | Select StatusCode,StatusDescription,Headers
19. HTTP Response Timing
Measure-Command {
Invoke-WebRequest https://example.com
}
Look for:
TotalMilliseconds
20. TLS Certificate Inspection
$tcp = New-Object Net.Sockets.TcpClient("example.com",443)
$ssl = New-Object Net.Security.SslStream(
$tcp.GetStream(),
$false
)
$ssl.AuthenticateAsClient("example.com")
$ssl.RemoteCertificate
21. Windows Firewall
| Task | Command |
|---|---|
| Firewall profiles | Get-NetFirewallProfile |
| All firewall rules | Get-NetFirewallRule |
| Enabled rules | Get-NetFirewallRule | Where-Object Enabled -eq "True" |
| Search rules | Get-NetFirewallRule | Where-Object DisplayName -like "*SSH*" |
| Port filters | Get-NetFirewallPortFilter |
22. Interface Metric
Get-NetIPInterface -AddressFamily IPv4 | Sort-Object InterfaceMetric
Useful when troubleshooting unexpected interface or route selection.
23. DHCP / IP Configuration
| Task | Command |
|---|---|
| IP configuration | Get-NetIPConfiguration |
| Interface configuration | Get-NetIPInterface |
| Traditional detailed configuration | ipconfig /all |
| Release DHCP address | ipconfig /release |
| Renew DHCP address | ipconfig /renew |
24. Network Profiles
Get-NetConnectionProfile
Shows information such as:
InterfaceAlias NetworkCategory IPv4Connectivity IPv6Connectivity
25. Adapter Details
Get-NetAdapter | Format-Table Name,InterfaceDescription,Status,LinkSpeed,MacAddress
Advanced NIC Properties
Get-NetAdapterAdvancedProperty
Specific interface:
Get-NetAdapterAdvancedProperty -Name "Ethernet"
26. MTU Troubleshooting
Display MTU
Get-NetIPInterface | Select InterfaceAlias,AddressFamily,NlMtu
Traditional:
netsh interface ipv4 show subinterfaces
Test MTU / Fragmentation
ping 8.8.8.8 -f -l 1472
Standard Ethernet calculation:
1472 byte ICMP payload + 20 byte IPv4 header + 8 byte ICMP header --------------------- = 1500 byte MTU
27. Useful PowerShell Filters
Find Routes Through a Next Hop
Get-NetRoute | Where-Object NextHop -eq "10.1.1.1"
Search DNS Cache
Get-DnsClientCache | Where-Object Entry -like "*aws*"
Find Connections to a Subnet
Get-NetTCPConnection | Where-Object RemoteAddress -like "10.192.*"
Find TCP 443 Connections
Get-NetTCPConnection | Where-Object RemotePort -eq 443
28. Network Engineer Top Commands
# ------------------------------------------------------ # IP / INTERFACES # ------------------------------------------------------ Get-NetIPConfiguration Get-NetIPAddress -AddressFamily IPv4 Get-NetAdapter Get-NetIPInterface -AddressFamily IPv4 # ------------------------------------------------------ # ROUTING # ------------------------------------------------------ Get-NetRoute -AddressFamily IPv4 Get-NetRoute -DestinationPrefix "0.0.0.0/0" Find-NetRoute -RemoteIPAddress 10.10.10.10 route print -4 # ------------------------------------------------------ # CONNECTIVITY # ------------------------------------------------------ ping 10.10.10.10 tracert -d 10.10.10.10 Test-NetConnection 10.10.10.10 Test-NetConnection server.company.com -Port 443 # ------------------------------------------------------ # DNS # ------------------------------------------------------ Resolve-DnsName server.company.com Resolve-DnsName server.company.com -Type A Resolve-DnsName server.company.com -Server 8.8.8.8 Get-DnsClientServerAddress Get-DnsClientCache Clear-DnsClientCache # ------------------------------------------------------ # ARP / NEIGHBOR # ------------------------------------------------------ Get-NetNeighbor -AddressFamily IPv4 arp -a # ------------------------------------------------------ # TCP # ------------------------------------------------------ Get-NetTCPConnection Get-NetTCPConnection -State Established Get-NetTCPConnection -State Listen netstat -ano # ------------------------------------------------------ # WINDOWS FIREWALL # ------------------------------------------------------ Get-NetFirewallProfile Get-NetFirewallRule # ------------------------------------------------------ # MTU # ------------------------------------------------------ Get-NetIPInterface | Select InterfaceAlias,AddressFamily,NlMtu ping 8.8.8.8 -f -l 1472
29. Five High-Value Troubleshooting Commands
Which Route Will Windows Use?
Find-NetRoute -RemoteIPAddress 10.192.10.50
Can I Establish TCP Connectivity?
Test-NetConnection hostname -Port 443 -InformationLevel Detailed
What Does a Specific DNS Server Return?
Resolve-DnsName hostname -Server DNS-SERVER-IP
What TCP Sessions Exist?
Get-NetTCPConnection -State Established
What is the Host’s Complete Layer-3 Configuration?
Get-NetIPConfiguration -Detailed
30. Basic Network Troubleshooting Workflow
# 1. Check local IP configuration Get-NetIPConfiguration -Detailed # 2. Check the route Windows will use Find-NetRoute -RemoteIPAddress 10.10.10.10 # 3. Check DNS Resolve-DnsName server.company.com # 4. Test basic reachability ping 10.10.10.10 # 5. Check the network path tracert -d 10.10.10.10 # 6. Test the actual application port Test-NetConnection server.company.com -Port 443 -InformationLevel Detailed # 7. Check existing TCP sessions Get-NetTCPConnection -State Established # 8. Check ARP / neighbor resolution Get-NetNeighbor -AddressFamily IPv4