show interfaces status is the fastest way to see every port on a Cisco switch: state, VLAN, speed, and duplex in one line per port. This guide reads the output column by column, decodes every status value (including err-disabled, with a real port-security violation as the demo), and covers the follow-up commands you run when a port is not doing what you expect. All output below is captured live from a Catalyst 9000 (IOS XE 17.18) in our CML lab.
New to VLAN? Start with the full VLAN and Layer 2 switching guide, then come back here for the deep dive.
The Command
From privileged EXEC:
ACC-SW1# show interfaces status
Port Name Status Vlan Duplex Speed Type
Gi1/0/1 UPLINK-TO-R2 connected 10 a-full a-1000 unknown
Gi1/0/2 HOST-PORT connected 10 a-full a-1000 unknown
Gi1/0/7 notconnect 1 auto auto unknown
Gi1/0/8 PARKED-PORT disabled 999 auto auto unknown
Gi1/0/9 notconnect 1 auto auto unknown(Output trimmed - a 24-port switch prints 24 rows.) The command is officially show interfaces status, plural, but IOS accepts any unambiguous abbreviation, so show int status and the commonly typed show interface status both work.
Reading the Columns
- Port - the interface (Gi1/0/1 = GigabitEthernet, switch 1, module 0, port 1).
- Name - the interface
description, truncated to fit. Ports without one are blank, which is exactly why you should set descriptions. - Status - the port state:
connected,notconnect,disabled, orerr-disabled. Details below. - Vlan - the access VLAN, or the word
trunkfor trunk ports, orroutedfor no-switchport L3 ports. - Duplex / Speed - the operating values. An
a-prefix (a-full,a-1000) means auto-negotiated; no prefix means hard-coded.autoalone means the port is down and nothing has negotiated yet. - Type - the physical media (10/100/1000BaseTX, SFP module type, and so on).
A trunk port shows up like this - note the Vlan column:
ACC-SW1# show interfaces status | include Gi1/0/2
Gi1/0/2 HOST-PORT connected trunk a-full a-1000 unknownThe Four Status Values
connected
Link is up and the port is passing traffic. This is the goal state.
notconnect
Nothing usable on the other end: unplugged cable, powered-off device, bad cable, or a speed/duplex hard-set mismatch that prevents link. The port is enabled and waiting.
disabled
Someone typed shutdown. The switch is doing exactly what it was told; no shutdown brings it back. Deliberately parking unused ports in a dead VLAN and shutting them (like our PARKED-PORT above) is standard hygiene.
err-disabled
The switch itself shut the port down after detecting a problem - port-security violation, BPDU guard, link flap, and a dozen other causes. Here is a real one: Gi1/0/1 has switchport port-security (max 1 MAC, violation mode shutdown), and a device with an unexpected MAC address just sent traffic:
*Aug 23 23:51:48.004: %PM-4-ERR_DISABLE: psecure-violation error detected on
Gi1/0/1, putting Gi1/0/1 in err-disable state
*Aug 23 23:51:48.007: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation
occurred, caused by MAC address 0000.dead.beef on port GigabitEthernet1/0/1.show interfaces status err-disabled lists exactly which ports are in this state and why:
ACC-SW1# show interfaces status err-disabled
Port Name Status Reason Err-disabled Vlans
Gi1/0/1 UPLINK-TO-R2 err-disabled psecure-violationFor port-security specifically, show port-security interface confirms the story and names the offending MAC:
ACC-SW1# show port-security interface GigabitEthernet1/0/1
Port Status : Secure-shutdown
Violation Mode : Shutdown
Last Source Address:Vlan : 0000.dead.beef:10
Security Violation Count : 1Fix the cause first (in our lab, the spoofed MAC), then bounce the port:
ACC-SW1(config)# interface GigabitEthernet1/0/1
ACC-SW1(config-if)# shutdown
ACC-SW1(config-if)# no shutdownACC-SW1# show interfaces GigabitEthernet1/0/1 status
Port Name Status Vlan Duplex Speed Type
Gi1/0/1 UPLINK-TO-R2 connected 10 a-full a-1000 unknownRe-enabling without fixing the cause just schedules the next violation. For automatic recovery, errdisable recovery cause psecure-violation plus errdisable recovery interval re-enables the port on a timer.
Checking a Single Interface
Scope the command to one port when you know where the problem is:
ACC-SW1# show interfaces GigabitEthernet1/0/1 statusOr filter the full table - show interfaces status err-disabled and | include filters both beat scrolling on a 48-port stack.
Related Commands Worth Knowing
show interfaces description gives the same one-line-per-port view but with Status/Protocol columns and full descriptions - admin down here corresponds to disabled in the status table:
ACC-SW1# show interfaces description
Interface Status Protocol Description
Gi1/0/1 up up UPLINK-TO-R2
Gi1/0/8 admin down down PARKED-PORTshow interfaces <port> counters errors is the follow-up when a port is connected but behaving badly - CRC, alignment, and collision counters point at cabling and duplex problems:
ACC-SW1# show interfaces GigabitEthernet1/0/2 counters errors
Port Align-Err FCS-Err Xmit-Err Rcv-Err UnderSize OutDiscards
Gi1/0/2 0 0 0 0 0 0And show ip interface brief is the router-side equivalent: L3 interfaces, IP addresses, and up/down state. On a switch, use it for SVIs and routed ports; use show interfaces status for switchports.
Check switch port status in the browser
The free IOS Essentials lab includes a checked show interfaces status exercise on SW1. No account or installation needed.
Quick Reference
FAQs
What does the show interfaces status command display?
One line per switchport: status (connected/notconnect/disabled/err-disabled), VLAN or trunk, duplex, speed, and media type. It is the quickest full-switch health view.
What does the a- prefix on duplex and speed mean?
Auto-negotiated. a-full a-1000 means the port negotiated full duplex at 1 Gbps. Values without the prefix were hard-coded, and a hard-coded port talking to an auto port is a classic duplex-mismatch source.
Why is an interface err-disabled?
The switch disabled it after detecting a violation or fault - port security, BPDU guard, link flapping, and others. show interfaces status err-disabled names the reason; fix the cause, then shutdown / no shutdown.
Key Takeaways
show interfaces statusis the one-screen state view for every switchport; scope it with an interface ID or theerr-disabledkeyword.notconnectis a cabling/far-end problem,disabledis an adminshutdown, anderr-disabledmeans the switch shut it down for cause - three different fixes.- The
a-prefix marks auto-negotiated speed/duplex; its absence marks hard-set values. - For err-disabled ports, always read the reason and the log before bouncing the port.
- Follow up with
counters errorswhen a connected port misbehaves.
Regularly checking interface status pairs well with a full port audit - see How to Conduct a Port Audit on Cisco Switches for finding unused ports and tightening security.