How to Check IP Addresses on Linux
On Linux, the IP address set on the server can be checked by ip address as a basic method. If you want to know which IP will be chosen for actual external communication, check the src value of ip route get destination, and the public IP visible on the internet needs to be checked separately due to NAT, proxy, or VPN.
ip -brief address ip route get 1.1.1.1
A single server can have multiple addresses at the same time, including loopback, private IPv4, public IPv4, link-local IPv6, global IPv6, etc. Therefore, "my IP" depends on which network you are trying to communicate with.
Quickest way to check IP address
View all interfaces simply
ip -brief address
-brief shows the interface name, status, and address in one line per interface. lo is the loopback interface for communicating with itself, and 127.0.0.1 and ::1 are not addresses for external devices to connect to.
View only IPv4 addresses
ip -4 address show
To narrow down to only global scope IPv4 addresses, execute as follows.
ip -4 address show scope global
View only IPv6 addresses
ip -6 address show
IPv6 can display both scope link addresses, which are only valid within the link, and scope global addresses, which are used on a wider scale. Since there can also be multiple temporary privacy addresses, check the address properties such as scope, temporary, and dynamic together.
How to read 'ip address' output
ip address show displays network interfaces and the protocol addresses attached to those interfaces in detail. You can check the command syntax and address properties in the ip-address manual.
ip address show
| Display items | Meaning | Things to check |
|---|---|---|
UP |
The interface is administratively up | This does not mean that the actual link and communication are normal. |
LOWER_UP |
The device's lower-layer link is up | Clues to determine the status of cable or virtual links. |
inet |
IPv4 address and prefix length | Displayed like 192.0.2.10/24. |
inet6 |
IPv6 address and prefix length | You need to distinguish between link-local and global addresses. |
scope |
Valid address scope | Includes host, link, global, etc. |
valid_lft |
Valid lifetime of the address | Dynamic addresses can change or be removed over time. |
Check a specific network interface
Find the interface name
ip -brief link
Depending on the environment, the name can be different, such as eth0, ens3, enp1s0, wlan0. Do not assume a specific name from documentation or scripts; check the actual system’s list first.
View the address of the selected interface
ip address show dev ens3
ens3 is an example. Replace it with the actual interface name. If only an IPv4 global address is needed, you can specify a condition together.
ip -4 address show dev ens3 scope global
Check the IP for actual external communication
Check src in the route lookup
If there are multiple addresses, the interface selected and the source address may vary depending on the destination. Check the routing decisions for a specific destination with ip route get.
ip route get 1.1.1.1
In the output, dev is the interface to use, via is the next gateway, and src is the source address chosen by the kernel. This command queries the routing table and does not guarantee that the connection to the target server or application will succeed. For detailed syntax, refer to the ip-route manual.
Checking the default gateway
ip route show default
If there are multiple default routes, the actual path may differ depending on the metric, policy routing rules, and destination. This is why it is recommended to check the ip route get results together.
Checking the IPv6 route
ip -6 route get 2606:4700:4700::1111
Even if IPv6 is configured, actual connectivity is only possible if the upstream router, firewall, DNS, and applications all support IPv6 communication.
Quickly checking with hostname -I
On some Linux distributions, the following command can output the addresses set on the host separated by spaces.
hostname -I
Short and convenient, but it does not show the interface name, prefix length, address range, or selected route. To determine which address is actually used for communication among multiple addresses, use ip address and ip route get.
hostname -i shows the result of name resolution, so it is affected by /etc/hosts or DNS settings and is different from querying the address directly set on the interface. It is important not to confuse similar options.
Distinguishing private IPs and public IPs
Local interface address
The addresses shown by ip address are set on the interfaces of that Linux network namespace. If behind a home router or cloud NAT, private IPv4 addresses in the ranges 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 may be visible.
Addresses visible on the internet
When passing through NAT, external services may see the public IP of the router, cloud gateway, VPN, or proxy. This address cannot be determined with local commands alone; the most reliable way is to check via network equipment or cloud management interface.
You can also use an external IP checking web service, but the request time and source address will be sent to that service. Choose a trusted service and consider automation dependencies, IPv4/IPv6 distinction, and potential failures.
Whether a port is open is a separate matter.
Knowing the public IP does not mean the server's service is accessible from the internet. You must check NAT port forwarding, cloud security groups, host firewalls, and the service's receiving address and port.
ss -lntup
Administrator privileges may be required to view process information. Before exposing a service externally, review authentication, encryption, update status, and the minimum allowed scope.
Handling IP addresses in scripts
Use JSON output
It is more reliable to structurally process ip JSON output than using grep combinations that depend on string positions.
ip -j -4 address show scope global
The JSON parser should iterate through interfaces and the addr_info array and handle the possibility of multiple addresses. Output fields may differ depending on the ip version, so verify on the target distribution.
Do not choose just one address unconditionally
In environments with multi-home servers, VPNs, containers, or temporary IPv6 addresses, there is no guarantee that the "first address" is the one an application needs. Select after clearly defining the destination, address family, interface, and scope conditions.
Containers and network namespaces
Running ip address inside a container generally shows the addresses of that container's network namespace. These may differ from the host's interface addresses or external NAT addresses.
Hosts, containers, Kubernetes Pods, services, ingress, and external load balancers can have different addresses. When diagnosing issues, record which namespace the command was executed in and distinguish each layer of the communication path.
Can I use ifconfig?
ifconfig is often seen in older documentation, but it may not be installed by default on recent Linux distributions and cannot fully represent modern networking features. In new documentation and scripts, it is recommended to prefer iproute2 commands such as ip address, ip link, and ip route.
If existing system operation procedures rely on ifconfig, do not remove it immediately. Instead, verify the differences in output and behavior and transition gradually.
Frequently Asked Questions
Is 127.0.0.1 the server's IP?
It is the IPv4 loopback address that refers to the server itself. Devices on the same network cannot access the server using this address.
If multiple addresses appear, which one should I use?
It depends on the counterpart you are trying to connect to and the route. For the same internal network, use the private address of the relevant interface. For the source address to use when going to a specific external destination, check the src in ip route get destination.
Why don’t I see a public IP in ip address?
It may be because the server is behind NAT, a load balancer, a VPN, or a proxy. Check the external address mapping in your network equipment or cloud console.
Can I connect via SSH just by knowing the IP address?
No. The SSH server must be listening on the appropriate address and port, routing/NAT/firewall/security groups must allow the connection, and a valid authentication method is also required.
Summary
You can check the interface address with ip -brief address, and detailed IPv4/IPv6 information with ip -4 address and ip -6 address. The source address that will actually be used for a destination is more accurately indicated by the src value of ip route get destination.
The local address and the public address visible on the Internet may differ due to NAT and proxies. Always specify the address range, the network namespace you executed, and the actual communication destination together.









