Skip to content

Network

Summary
  • Linux networking boils down to four layers you'll keep coming back to: interfaces (the physical/virtual NICs), addressing (IPs and subnets), routing (how packets find their way out), and DNS (turning names into addresses).
  • Modern Linux uses the iproute2 toolset (ip, ss) — the older net-tools commands (ifconfig, route, netstat) still work on most distros but are considered deprecated.1
  • Almost every networking problem on a Linux box can be diagnosed by walking through these four layers in order: is the interface up? does it have the right IP? does it have a route out? can it resolve names?

Think of this page as:

"The four questions to ask, in order, whenever 'the network' doesn't work: is the cable/interface actually up, do I have an address, do I have a way out, and can I turn names into addresses?"

If you are confused...

If you've read the Bash page, most of what follows is just more commands to run at that same prompt — nothing here requires anything beyond a normal shell.

Network Interfaces

Every network connection — wired, wireless, or virtual — is represented as an interface. Modern distros name them predictably based on hardware/location (enp0s3, wlp2s0) rather than the old generic eth0/wlan0 scheme, though both still show up depending on the distro and driver.

ip link show      # list interfaces and their up/down state
ip link set eth0 up    # bring an interface up
ip link set eth0 down  # bring an interface down

IP Addressing

An IP address always comes with a subnet mask — usually written in CIDR notation (/24, /16, etc.) — which defines how much of the address identifies the network vs. the specific host.

CIDR Subnet Mask Usable Hosts
/8 255.0.0.0 ~16.7 million
/16 255.255.0.0 ~65,000
/24 255.255.255.0 254
/30 255.255.255.252 2 (common for point-to-point links)

Common CIDR Blocks

Private address ranges (RFC 1918)

Three IPv4 ranges are reserved for private networks and never routed on the public internet: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.2 If you see one of these, you're behind NAT somewhere.

ip addr show           # list interfaces and their assigned IPs
ip addr add 192.168.1.50/24 dev eth0   # manually assign an IP

Routing

Once an interface has an address, the system needs to know where to send traffic that isn't on the local subnet — that's the default route (a.k.a. default gateway).

ip route show           # show the full routing table
ip route show default   # show just the default route

A typical routing table entry looks like:

default via 192.168.1.1 dev eth0
192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.50

The first line says "anything not otherwise matched goes to 192.168.1.1"; the second says "anything in 192.168.1.0/24 is directly reachable on eth0, no gateway needed."

Configuring an Interface

There are two fundamentally different ways to get an interface addressed: manually (you set everything yourself) and automatically (something else — almost always DHCP — does it for you). Most systems default to automatic and only need manual configuration for servers, routers, or anything that needs a stable, predictable address.

Manual Configuration

Temporary — applied immediately, but lost on reboot. Good for testing:

sudo ip addr add 192.168.1.50/24 dev eth0
sudo ip link set eth0 up
sudo ip route add default via 192.168.1.1

Persistent — survives a reboot, but where it lives depends entirely on which network management tool your distro actually uses:

# /etc/netplan/01-netcfg.yaml
network:
    version: 2
    ethernets:
    eth0:
        addresses:
        - 192.168.1.50/24
        routes:
        - to: default
            via: 192.168.1.1
        nameservers:
        addresses: [8.8.8.8, 1.1.1.1]
Apply with `sudo netplan apply`.
# /etc/systemd/network/10-eth0.network
[Match]
Name=eth0

[Network]
Address=192.168.1.50/24
Gateway=192.168.1.1
DNS=8.8.8.8
Apply with `sudo systemctl restart systemd-networkd`.
sudo nmcli con mod eth0 ipv4.addresses 192.168.1.50/24
sudo nmcli con mod eth0 ipv4.gateway 192.168.1.1
sudo nmcli con mod eth0 ipv4.dns 8.8.8.8
sudo nmcli con mod eth0 ipv4.method manual
sudo nmcli con up eth0
# /etc/network/interfaces
auto eth0
iface eth0 inet static
    address 192.168.1.50
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
Apply with `sudo ifdown eth0 && sudo ifup eth0`.

Automatic Configuration (DHCP)

Most of the time, a DHCP (Dynamic Host Configuration Protocol) server already on the network hands out an IP, subnet, gateway, and DNS servers automatically — no manual configuration needed at all.

network:
    version: 2
    ethernets:
    eth0:
        dhcp4: true
[Match]
Name=eth0

[Network]
DHCP=yes
sudo nmcli con mod eth0 ipv4.method auto
sudo nmcli con up eth0
sudo dhclient eth0   # request/renew a DHCP lease on demand

Which tool is my distro actually using?

  • Ubuntu Desktop/Server 18.04+ → netplan (typically with NetworkManager as the backend on Desktop, systemd-networkd on Server)
  • Debian (classic) → ifupdown, unless changed
  • Fedora / RHEL / CentOS → NetworkManager
  • Arch, minimal server installs → often bare systemd-networkd

Not sure which one's actually active? Check for a running nmcli, or look for /etc/netplan/*.yaml, /etc/systemd/network/*.network, or /etc/network/interfaces to see what's actually configured.

DNS

DNS turns names into IP addresses, but Linux checks more than one source before it even asks a DNS server:

  1. /etc/hosts — static, manually-defined name→IP mappings, checked first by default
  2. /etc/resolv.conf — lists the actual DNS server(s) to query (nameserver 8.8.8.8, for example)
  3. /etc/nsswitch.conf — controls the overall lookup order (hosts: files dns is the common default, meaning /etc/hosts is checked before DNS)
dig example.com          # detailed DNS query, shows the full response
host example.com         # quick, simple lookup
nslookup example.com     # older, still widely available lookup tool

Common Networking Commands

Command Purpose
ping <host> Test basic reachability and round-trip latency
traceroute <host> Show the path (hop by hop) packets take to a destination
mtr <host> A continuously-updating combination of ping and traceroute
ss -tulpn List listening TCP/UDP sockets, with the process using each one
curl <url> Fetch a URL — the go-to tool for testing HTTP(S) connectivity
wget <url> Download a file over HTTP(S)/FTP
nmap <host> Scan a host for open ports and running services
tcpdump -i eth0 Capture raw packets on an interface for inspection

Common Networking Commands

ss vs. netstat?

ss (socket statistics) is the modern replacement for netstat — faster, and pulls its data directly from the kernel rather than parsing /proc. netstat still works on most systems, but ss is what you'll see recommended in current documentation.1

Firewalls

Linux firewalling happens in the kernel via netfilter, but you'll usually interact with it through a higher-level tool rather than netfilter directly:

  • iptables — the long-standing, rule-based classic (still widely deployed, especially on older systems)
  • nftables — netfilter's modern replacement for iptables, with a cleaner syntax
  • ufw (Uncomplicated Firewall) — a friendlier frontend over iptables/nftables, common on Ubuntu/Debian
  • firewalld — a dynamic, zone-based frontend common on Red Hat/Fedora/CentOS
sudo ufw status          # check firewall status (Debian/Ubuntu)
sudo ufw allow 22/tcp    # allow SSH
sudo firewall-cmd --state    # check firewall status (RHEL/Fedora)

Useful Resources


  1. Linux Foundation. (n.d.). iproute2. Linux Foundation Wiki. https://wiki.linuxfoundation.org/networking/iproute2 ↩↩

  2. Rekhter, Y., Moskowitz, B., Karrenberg, D., de Groot, G. J., & Lear, E. (1996). Address allocation for private internets (RFC 1918). IETF. https://www.rfc-editor.org/rfc/rfc1918 ↩