Show Interfaces Status on Cisco Switches: Reading Every Column

One line per port: state, VLAN, duplex, speed. How to read every column of show interfaces status, decode all four status values, and recover an err-disabled port - with real Catalyst output.

Mastering ‘Show Interface Status’ in Cisco: Top 5 Essential Tips - PingLabz VLAN article title card

show interfaces status is the fastest way to see every port on a Cisco switch: state, VLAN, speed, and duplex in one line per port. This guide reads the output column by column, decodes every status value (including err-disabled, with a real port-security violation as the demo), and covers the follow-up commands you run when a port is not doing what you expect. All output below is captured live from a Catalyst 9000 (IOS XE 17.18) in our CML lab.

New to VLAN? Start with the full VLAN and Layer 2 switching guide, then come back here for the deep dive.

The Command

From privileged EXEC:

ACC-SW1# show interfaces status

Port         Name               Status       Vlan       Duplex  Speed Type
Gi1/0/1      UPLINK-TO-R2       connected    10         a-full a-1000 unknown
Gi1/0/2      HOST-PORT          connected    10         a-full a-1000 unknown
Gi1/0/7                         notconnect   1            auto   auto unknown
Gi1/0/8      PARKED-PORT        disabled     999          auto   auto unknown
Gi1/0/9                         notconnect   1            auto   auto unknown

(Output trimmed - a 24-port switch prints 24 rows.) The command is officially show interfaces status, plural, but IOS accepts any unambiguous abbreviation, so show int status and the commonly typed show interface status both work.

Reading the Columns

  • Port - the interface (Gi1/0/1 = GigabitEthernet, switch 1, module 0, port 1).
  • Name - the interface description, truncated to fit. Ports without one are blank, which is exactly why you should set descriptions.
  • Status - the port state: connected, notconnect, disabled, or err-disabled. Details below.
  • Vlan - the access VLAN, or the word trunk for trunk ports, or routed for no-switchport L3 ports.
  • Duplex / Speed - the operating values. An a- prefix (a-full, a-1000) means auto-negotiated; no prefix means hard-coded. auto alone means the port is down and nothing has negotiated yet.
  • Type - the physical media (10/100/1000BaseTX, SFP module type, and so on).

A trunk port shows up like this - note the Vlan column:

ACC-SW1# show interfaces status | include Gi1/0/2
Gi1/0/2      HOST-PORT          connected    trunk      a-full a-1000 unknown

The Four Status Values

connected

Link is up and the port is passing traffic. This is the goal state.

notconnect

Nothing usable on the other end: unplugged cable, powered-off device, bad cable, or a speed/duplex hard-set mismatch that prevents link. The port is enabled and waiting.

disabled

Someone typed shutdown. The switch is doing exactly what it was told; no shutdown brings it back. Deliberately parking unused ports in a dead VLAN and shutting them (like our PARKED-PORT above) is standard hygiene.

err-disabled

The switch itself shut the port down after detecting a problem - port-security violation, BPDU guard, link flap, and a dozen other causes. Here is a real one: Gi1/0/1 has switchport port-security (max 1 MAC, violation mode shutdown), and a device with an unexpected MAC address just sent traffic:

*Aug 23 23:51:48.004: %PM-4-ERR_DISABLE: psecure-violation error detected on
  Gi1/0/1, putting Gi1/0/1 in err-disable state
*Aug 23 23:51:48.007: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation
  occurred, caused by MAC address 0000.dead.beef on port GigabitEthernet1/0/1.

show interfaces status err-disabled lists exactly which ports are in this state and why:

ACC-SW1# show interfaces status err-disabled

Port         Name         Status       Reason               Err-disabled Vlans
Gi1/0/1      UPLINK-TO-R2 err-disabled psecure-violation

For port-security specifically, show port-security interface confirms the story and names the offending MAC:

ACC-SW1# show port-security interface GigabitEthernet1/0/1
Port Status                : Secure-shutdown
Violation Mode             : Shutdown
Last Source Address:Vlan   : 0000.dead.beef:10
Security Violation Count   : 1

Fix the cause first (in our lab, the spoofed MAC), then bounce the port:

ACC-SW1(config)# interface GigabitEthernet1/0/1
ACC-SW1(config-if)# shutdown
ACC-SW1(config-if)# no shutdown
ACC-SW1# show interfaces GigabitEthernet1/0/1 status

Port         Name               Status       Vlan       Duplex  Speed Type
Gi1/0/1      UPLINK-TO-R2       connected    10         a-full a-1000 unknown

Re-enabling without fixing the cause just schedules the next violation. For automatic recovery, errdisable recovery cause psecure-violation plus errdisable recovery interval re-enables the port on a timer.

Checking a Single Interface

Scope the command to one port when you know where the problem is:

ACC-SW1# show interfaces GigabitEthernet1/0/1 status

Or filter the full table - show interfaces status err-disabled and | include filters both beat scrolling on a 48-port stack.

show interfaces description gives the same one-line-per-port view but with Status/Protocol columns and full descriptions - admin down here corresponds to disabled in the status table:

ACC-SW1# show interfaces description
Interface                      Status         Protocol Description
Gi1/0/1                        up             up       UPLINK-TO-R2
Gi1/0/8                        admin down     down     PARKED-PORT

show interfaces <port> counters errors is the follow-up when a port is connected but behaving badly - CRC, alignment, and collision counters point at cabling and duplex problems:

ACC-SW1# show interfaces GigabitEthernet1/0/2 counters errors

Port           Align-Err     FCS-Err    Xmit-Err     Rcv-Err  UnderSize  OutDiscards
Gi1/0/2                0           0           0           0          0            0

And show ip interface brief is the router-side equivalent: L3 interfaces, IP addresses, and up/down state. On a switch, use it for SVIs and routed ports; use show interfaces status for switchports.

Check switch port status in the browser

The free IOS Essentials lab includes a checked show interfaces status exercise on SW1. No account or installation needed.

Start free Essentials

Quick Reference

show interfaces status
All ports: state, VLAN, duplex, speed
show interfaces [id] status
Same view, one port
show interfaces status err-disabled
Err-disabled ports and the reason
show interfaces description
Status/Protocol plus full descriptions
show interfaces [id] counters errors
CRC, alignment, collision counters
shutdown / no shutdown
Disable / enable a port (also clears err-disable)

FAQs

What does the show interfaces status command display?

One line per switchport: status (connected/notconnect/disabled/err-disabled), VLAN or trunk, duplex, speed, and media type. It is the quickest full-switch health view.

What does the a- prefix on duplex and speed mean?

Auto-negotiated. a-full a-1000 means the port negotiated full duplex at 1 Gbps. Values without the prefix were hard-coded, and a hard-coded port talking to an auto port is a classic duplex-mismatch source.

Why is an interface err-disabled?

The switch disabled it after detecting a violation or fault - port security, BPDU guard, link flapping, and others. show interfaces status err-disabled names the reason; fix the cause, then shutdown / no shutdown.

Key Takeaways

  • show interfaces status is the one-screen state view for every switchport; scope it with an interface ID or the err-disabled keyword.
  • notconnect is a cabling/far-end problem, disabled is an admin shutdown, and err-disabled means the switch shut it down for cause - three different fixes.
  • The a- prefix marks auto-negotiated speed/duplex; its absence marks hard-set values.
  • For err-disabled ports, always read the reason and the log before bouncing the port.
  • Follow up with counters errors when a connected port misbehaves.

Regularly checking interface status pairs well with a full port audit - see How to Conduct a Port Audit on Cisco Switches for finding unused ports and tightening security.

References

Read next