Skip to content

ip: Network Setup and Diagnostics in CLI

When ifconfig returns nothing and configuring a route requires a separate command, that’s not a system bug. It’s iproute2 — the package that replaced net-tools in modern Linux distributions. The ip utility from iproute2 is the standard interface for managing the Linux network stack. It covers interfaces, addresses, routes, ARP cache, routing policies, and namespace isolation.

Why iproute2 replaced net-tools

net-tools (ifconfig, route, arp, netstat, nameif) originated in BSD and migrated to Linux in the 1990s. By the 2000s it became clear: they cannot handle VLAN, IPsec, QoS, multicast routing, or Policy Routing. Each task required a separate command with unrelated syntax.

iproute2 consolidated everything into one ip utility with subcommands. The Linux kernel communicates with the network subsystem via netlink sockets — ip talks to them directly, while ifconfig parses /proc/net/. In systemd-based distributions (RHEL 7+, Ubuntu 16.04+, Debian 9+) ip is installed by default. net-tools remains in repositories for compatibility, but kernel developers haven’t added new functionality since 2001.

Install if needed: apt install iproute2 or yum install iproute.

ip link operates at L2 — listing and controlling interface state.

ip link show
ip link show eth0
ip link show type bridge

Output shows index, name, MAC address, MTU, state (UP/DOWN), and error/packet counters.

Bring an interface up or down:

ip link set eth0 up
ip link set eth0 down
Warning

Taking down an interface severs connectivity. When working remotely, wrap in a script with a timeout and auto-recovery.

Set MTU, change MAC, or rename:

ip link set eth0 mtu 9000
ip link set eth0 address 02:42:ac:11:00:02
ip link set eth0 name enp0s3

Create virtual interfaces (VETH pair for namespace or bridge):

ip link add veth0 type veth peer name veth1
ip link add br0 type bridge
ip link set veth0 master br0

Delete an interface:

ip link del veth0
FlagPurpose
showdisplay interfaces (shorthand: ip l)
setmodify interface parameters
add / delcreate or delete virtual interface
masterattach interface to a bridge

ip addr: address binding and diagnostics

ip addr manages IP addresses (L3).

ip addr show
ip addr show eth0

Add an address:

ip addr add 192.168.1.10/24 dev eth0

Add a secondary address (alias) on the same interface:

ip addr add 192.168.1.11/24 dev eth0
Note

Secondary addresses in Linux are not aliases in the ifconfig sense — they are part of a single address entity. The command ifconfig eth0:0 created a pseudodevice with a separate name; ip works differently.

Remove an address:

ip addr del 192.168.1.10/24 dev eth0

Flush all addresses from an interface:

ip addr flush dev eth0

Useful during reconfiguration: clear old addresses and assign new ones without restarting the service.

Specify scope and label:

ip addr add 10.0.0.5/8 dev eth0 scope host label eth0:internal

scope host — address only for local sockets; scope global — routable.

SubcommandAction
addassign address
delremove address
showdisplay addresses
flushclear interface addresses

ip route: default and static routes

ip route works with the routing table.

ip route show

Add a default route (gateway):

ip route add default via 192.168.1.1 dev eth0

Add a specific route:

ip route add 10.20.0.0/16 via 192.168.1.254 dev eth0

Route to a host via direct ARP (no route, L2 only):

ip route add 192.168.1.50/32 dev eth0

Remove a route:

ip route del default via 192.168.1.1

Replace a route (updates if exists, creates if not):

ip route replace default via 10.0.0.1 dev eth0

Get the route the kernel will choose for an address:

ip route get 8.8.8.8

Add a route to a different table (default is table 254):

ip route add default via 10.0.0.1 dev eth0 table 100
SubcommandPurpose
show / listdisplay routing table
addadd a route
delremove a route
replacemodify or create a route
getshow route to an address
flushclear route cache

ip neigh: ARP/NDP cache

ip neigh manages the neighbour table — ARP for IPv4, NDP for IPv6.

ip neigh show
ip neigh show dev eth0

Add a static ARP entry:

ip neigh add 192.168.1.1 lladdr 00:11:22:33:44:55 dev eth0 nud permanent

nud (Neighbour Unreachability Detection) defines the state:

  • permanent — entry never expires
  • noarp — managed by protocol but not removed
  • reachable / stale / delay / probe — automatic states

Remove an entry:

ip neigh del 192.168.1.1 dev eth0

Flush all neighbours on an interface:

ip neigh flush dev eth0
Tip

After changing a gateway MAC address, flushing the ARP cache speeds up connectivity recovery: ip neigh flush dev eth0.

ip rule: routing policies

ip rule determines which routing table is used for a packet.

ip rule show

Standard output:

0:      from all lookup local
32766:  from all lookup main
32767:  from all lookup default

Add a rule for source IP:

ip rule add from 10.0.0.5 table 100

Rule for incoming interface:

ip rule add iif eth0 table 100

Remove a rule:

ip rule del from 10.0.0.5 table 100
Note

Rules are checked in order (priority). Low number means high priority. Add rules with priority between existing ones if ordering matters.

ActionPurpose
fromsource IP or CIDR
todestination IP or CIDR
iifincoming interface
lookuprouting table
prionumeric priority

ip maddr: multicast addresses

ip maddr displays and manages multicast groups on an interface.

ip maddr show eth0

Add an interface to a multicast group:

ip maddr add 239.0.0.1 dev eth0

Remove:

ip maddr del 239.0.0.1 dev eth0

Unlike unicast, multicast addressing is used in broadcast domains, routing protocols (OSPF, RIP), discovery services, and streaming. In most tasks this command is unnecessary, but when configuring clusters or monitoring via specific protocols — it will be required.

ip netns: network stack isolation

ip netns creates isolated network namespaces. Each namespace has its own interfaces, addresses, routes, ARP table, and rules.

Create a namespace:

ip netns add testns

Run a command inside a namespace:

ip netns exec testns ip link show

Bring up an interface in a namespace:

ip netns exec testns ip link set lo up
ip netns exec testns ip addr add 127.0.0.1/8 dev lo

Move a VETH interface into a namespace:

ip link set veth1 netns testns

Delete a namespace:

ip netns del testns

List namespaces:

ip netns list
Tip

Containers (docker, podman, LXC) use netns underneath. If a container has no network — check the host namespace: ip netns exec <container_pid> ip addr.

ifconfig, arp, route — legacy compatibility

net-tools is formally available in all major distribution repositories. The source code is unmaintained, but packages persist for compatibility.

Legacy commandEquivalent ipStatus
ifconfigip addr, ip linkdeprecated
route -nip routedeprecated
arp -aip neighdeprecated
netstat -tulpnss -tulpndeprecated
nameifip link namedeprecated

ss from iproute2 replaces netstat — faster and provides more socket information.

Warning

Network initialization scripts in old distributions may rely on ifconfig. On modern systems, systemd-networkd, NetworkManager, and cloud-init use ip directly or through their own abstractions.

If ifconfig is missing in a fresh distribution — that’s expected. Configuration via ip covers all current scenarios: from address assignment to complex routing policies and service isolation via namespaces.