The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show active configurationGet-NetIPConfigurationView examples
Include disconnected interfacesGet-NetIPConfiguration -AllView examples
List IPv4 addressesGet-NetIPAddress -AddressFamily IPv4View examples
Inspect interface stateGet-NetIPInterface | Sort-Object InterfaceMetricView examples
Show IPv4 routesGet-NetRoute -AddressFamily IPv4 | Sort-Object RouteMetricView examples
Find the selected routeFind-NetRoute -RemoteIPAddress 1.1.1.1View examples
Inspect neighbor stateGet-NetNeighbor -AddressFamily IPv4View examples
Resolve IPv4 recordsResolve-DnsName -Name example.com -Type AView examples
Query a specific DNS serverResolve-DnsName -Name example.com -Type A -Server ` 192.0.2.53View examples
Clear the client DNS cacheClear-DnsClientCache -WhatIfView examples
Test ICMP reachabilityTest-Connection -TargetName example.com -Count 4View examples
Test a hostTest-NetConnection -ComputerName example.comView examples
Test a TCP portTest-NetConnection -ComputerName example.com -Port 443 ` -InformationLevel DetailedView examples
Trace the routeTest-NetConnection -ComputerName example.com -TraceRouteView examples
Show TCP listenersGet-NetTCPConnection -State Listen | Sort-Object LocalPortView examples
Show established TCP sessionsGet-NetTCPConnection -State EstablishedView examples
Show UDP endpointsGet-NetUDPEndpoint | Sort-Object LocalPortView examples
Map a socket to its processGet-Process -Id (Get-NetTCPConnection -LocalPort ` 443).OwningProcessView examples
Capture a port-test object$test = Test-NetConnection example.com -Port 443 ` -InformationLevel DetailedView examples

Troubleshoot Windows networking one layer at a time: local configuration, route selection, name resolution, IP reachability, transport ports, then the application. PowerShell returns objects, so preserve their properties for filtering and evidence instead of parsing formatted screen output.

Step by step

Detailed examples

01

Inventory interfaces, addresses, gateways, and DNS

Start with Get-NetIPConfiguration to see the configuration Windows considers active. Use -All when a virtual or disconnected adapter may influence the problem, then inspect Get-NetIPAddress and Get-NetIPInterface objects rather than their default table alone. Interface metrics help Windows choose among otherwise comparable routes; a lower combined route and interface metric is preferred.

Summarize active interface configuration
Get-NetIPConfiguration | Select-Object `
    InterfaceAlias, InterfaceIndex, `
    @{Name='IPv4'; Expression={$_.IPv4Address.IPAddress}}, `
    @{Name='Gateway'; Expression={$_.IPv4DefaultGateway.NextHop}}, `
    @{Name='DnsServer'; Expression={$_.DNSServer.ServerAddresses -join ', '}}
Output
InterfaceAlias : Ethernet
InterfaceIndex : 12
IPv4           : 192.0.2.20
Gateway        : 192.0.2.1
DnsServer      : 192.0.2.53
Review IPv4 addresses and interface preference
Get-NetIPAddress -AddressFamily IPv4 |
    Select-Object InterfaceAlias, IPAddress, PrefixLength, AddressState
Get-NetIPInterface | Sort-Object InterfaceMetric |
    Select-Object InterfaceAlias, AddressFamily, ConnectionState, InterfaceMetric
Output
# Output varies with physical, virtual, and tunnel interfaces.
Back to quick reference ↑
02

Inspect the route Windows will actually choose

Get-NetRoute inventories routing entries, but sorting only by RouteMetric is not a complete selection model because prefix length and interface metric also matter. Find-NetRoute asks Windows for the best path to one literal remote IP and returns two objects: the selected local IP address followed by the route. Neighbor state helps isolate failures on the local link.

Find the path to one destination
$localAddress, $route = Find-NetRoute -RemoteIPAddress 1.1.1.1
[pscustomobject]@{
    SourceAddress = $localAddress.IPAddress
    Interface = $route.InterfaceAlias
    NextHop = $route.NextHop
    RouteMetric = $route.RouteMetric
}

Get-NetNeighbor -InterfaceIndex $route.InterfaceIndex -AddressFamily IPv4
Output
SourceAddress : 192.0.2.20
Interface     : Ethernet
NextHop       : 192.0.2.1
RouteMetric   : 0

# Neighbor entries include IPAddress, LinkLayerAddress, and State.
Back to quick reference ↑
03

Query DNS independently from transport tests

Resolve-DnsName exposes record types, server responses, and errors directly. Compare the configured resolver with a known organizational DNS server only when that server is authorized and reachable. Clear-DnsClientCache changes local state and can hide useful evidence, so preview with -WhatIf and capture current results before clearing it.

Compare A records from two resolvers
Resolve-DnsName -Name example.com -Type A |
    Select-Object Name, Type, IPAddress
Resolve-DnsName -Name example.com -Type A -Server 192.0.2.53 |
    Select-Object Name, Type, IPAddress
Output
Name        Type IPAddress
----        ---- ---------
example.com A    192.0.2.10
Preview a DNS cache reset
Clear-DnsClientCache -WhatIf
Output
What if: Performing the operation 'Clear' on target 'DNS Client Cache'.
Back to quick reference ↑
04

Treat ICMP as one diagnostic signal

Test-Connection sends ICMP echo requests and, in modern PowerShell, emits objects that can be measured or exported. A failed echo can mean filtering rather than host failure, and a successful echo says nothing about a required TCP port or application. Bound the count and test the same hostname or address family used by the failing workload.

Measure four echo replies
$replies = Test-Connection -TargetName example.com -Count 4
$replies | Select-Object Address, Status, Latency
$replies | Measure-Object -Property Latency -Average -Minimum -Maximum
Output
Address      Status  Latency
-------      ------  -------
192.0.2.10   Success 18
192.0.2.10   Success 19
192.0.2.10   Success 17
192.0.2.10   Success 20

Count   : 4
Average : 18.5
Minimum : 17
Maximum : 20
Back to quick reference ↑
05

Test the required host and TCP port

Test-NetConnection combines several Windows diagnostics. With -Port, TcpTestSucceeded answers whether a TCP handshake completed; it does not validate TLS, authentication, or application content. -TraceRoute can reveal the visible hop path, but firewalls may suppress replies. Retain the detailed object so source address, interface, next hop, and result can be compared across machines.

Test HTTPS connectivity and inspect selected properties
$test = Test-NetConnection `
    -ComputerName example.com `
    -Port 443 `
    -InformationLevel Detailed
$test | Select-Object ComputerName, RemoteAddress, RemotePort, `
    InterfaceAlias, SourceAddress, NetRoute, TcpTestSucceeded
Output
ComputerName     : example.com
RemoteAddress    : 192.0.2.10
RemotePort       : 443
InterfaceAlias   : Ethernet
SourceAddress    : 192.0.2.20
TcpTestSucceeded : True
Trace visible network hops
Test-NetConnection -ComputerName example.com -TraceRoute
Output
ComputerName           : example.com
RemoteAddress          : 192.0.2.10
TraceRoute             : {192.0.2.1, 198.51.100.1, 192.0.2.10}
Back to quick reference ↑
06

Inspect local TCP and UDP endpoint objects

Get-NetTCPConnection and Get-NetUDPEndpoint replace fragile parsing of netstat text with filterable objects. A TCP listener exposes LocalAddress, LocalPort, State, and OwningProcess; mapping that identifier through Get-Process identifies the current owner, subject to access permissions and process lifetime. UDP is connectionless, so its endpoint objects do not have TCP-style connection states.

List listeners with process names
Get-NetTCPConnection -State Listen | ForEach-Object {
    $process = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
    [pscustomobject]@{
        Address = $_.LocalAddress
        Port = $_.LocalPort
        PID = $_.OwningProcess
        Process = $process.ProcessName
    }
} | Sort-Object Port
Output
Address   Port PID  Process
-------   ---- ---  -------
0.0.0.0     80 4120 webserver
127.0.0.1 8080 6224 app
Review established TCP and local UDP endpoints
Get-NetTCPConnection -State Established |
    Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, OwningProcess
Get-NetUDPEndpoint | Sort-Object LocalPort |
    Select-Object LocalAddress, LocalPort, OwningProcess
Output
# Results are live snapshots and can change between commands.
Back to quick reference ↑
07

Capture a layered, read-only diagnostic record

Collect configuration, route, DNS, transport, and endpoint evidence before changing adapters, caches, routes, or firewall rules. Structured objects can be exported for comparison, but review them for internal addresses, hostnames, and process details before sharing. When one layer succeeds, continue testing the actual layer the application requires.

Collect focused diagnostics
$target = 'example.com'
$address = Resolve-DnsName -Name $target -Type A | Select-Object -First 1
$localAddress, $route = Find-NetRoute -RemoteIPAddress $address.IPAddress
$test = Test-NetConnection -ComputerName $target -Port 443 -InformationLevel Detailed

[pscustomobject]@{
    CheckedAt = Get-Date
    Target = $target
    RemoteAddress = $address.IPAddress
    Interface = $route.InterfaceAlias
    SourceAddress = $localAddress.IPAddress
    Tcp443 = $test.TcpTestSucceeded
}
Output
CheckedAt     : 08/12/2026 14:30:00
Target        : example.com
RemoteAddress : 192.0.2.10
Interface     : Ethernet
SourceAddress : 192.0.2.20
Tcp443        : True
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnNetTCPIP PowerShell modulelearn.microsoft.com
  2. Microsoft LearnGet-NetIPConfigurationlearn.microsoft.com
  3. Microsoft LearnFind-NetRoutelearn.microsoft.com
  4. Microsoft LearnTest-NetConnectionlearn.microsoft.com
  5. Microsoft LearnResolve-DnsNamelearn.microsoft.com
  6. Microsoft LearnGet-NetTCPConnectionlearn.microsoft.com
  7. Microsoft LearnTest-Connectionlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback