Network¶
Summary
- Linux networking boils down to four layers you'll keep coming back to: interfaces (the physical/virtual NICs), addressing (IPs and subnets), routing (how packets find their way out), and DNS (turning names into addresses).
- Modern Linux uses the
iproute2toolset (ip,ss) — the oldernet-toolscommands (ifconfig,route,netstat) still work on most distros but are considered deprecated.1 - Almost every networking problem on a Linux box can be diagnosed by walking through these four layers in order: is the interface up? does it have the right IP? does it have a route out? can it resolve names?
Think of this page as:
"The four questions to ask, in order, whenever 'the network' doesn't work: is the cable/interface actually up, do I have an address, do I have a way out, and can I turn names into addresses?"
If you are confused...
If you've read the Bash page, most of what follows is just more commands to run at that same prompt — nothing here requires anything beyond a normal shell.
Network Interfaces¶
Every network connection — wired, wireless, or virtual — is represented as an interface. Modern distros name them predictably based on hardware/location (enp0s3, wlp2s0) rather than the old generic eth0/wlan0 scheme, though both still show up depending on the distro and driver.
ip link show # list interfaces and their up/down state
ip link set eth0 up # bring an interface up
ip link set eth0 down # bring an interface down
IP Addressing¶
An IP address always comes with a subnet mask — usually written in CIDR notation (/24, /16, etc.) — which defines how much of the address identifies the network vs. the specific host.
| CIDR | Subnet Mask | Usable Hosts |
|---|---|---|
/8 |
255.0.0.0 |
~16.7 million |
/16 |
255.255.0.0 |
~65,000 |
/24 |
255.255.255.0 |
254 |
/30 |
255.255.255.252 |
2 (common for point-to-point links) |
Common CIDR Blocks
Private address ranges (RFC 1918)
Three IPv4 ranges are reserved for private networks and never routed on the public internet: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.2 If you see one of these, you're behind NAT somewhere.
ip addr show # list interfaces and their assigned IPs
ip addr add 192.168.1.50/24 dev eth0 # manually assign an IP
Routing¶
Once an interface has an address, the system needs to know where to send traffic that isn't on the local subnet — that's the default route (a.k.a. default gateway).
A typical routing table entry looks like:
The first line says "anything not otherwise matched goes to 192.168.1.1"; the second says "anything in 192.168.1.0/24 is directly reachable on eth0, no gateway needed."
Configuring an Interface¶
There are two fundamentally different ways to get an interface addressed: manually (you set everything yourself) and automatically (something else — almost always DHCP — does it for you). Most systems default to automatic and only need manual configuration for servers, routers, or anything that needs a stable, predictable address.
Manual Configuration¶
Temporary — applied immediately, but lost on reboot. Good for testing:
sudo ip addr add 192.168.1.50/24 dev eth0
sudo ip link set eth0 up
sudo ip route add default via 192.168.1.1
Persistent — survives a reboot, but where it lives depends entirely on which network management tool your distro actually uses:
# /etc/netplan/01-netcfg.yaml
network:
version: 2
ethernets:
eth0:
addresses:
- 192.168.1.50/24
routes:
- to: default
via: 192.168.1.1
nameservers:
addresses: [8.8.8.8, 1.1.1.1]
Apply with `sudo netplan apply`.
# /etc/systemd/network/10-eth0.network
[Match]
Name=eth0
[Network]
Address=192.168.1.50/24
Gateway=192.168.1.1
DNS=8.8.8.8
Apply with `sudo systemctl restart systemd-networkd`.
sudo nmcli con mod eth0 ipv4.addresses 192.168.1.50/24
sudo nmcli con mod eth0 ipv4.gateway 192.168.1.1
sudo nmcli con mod eth0 ipv4.dns 8.8.8.8
sudo nmcli con mod eth0 ipv4.method manual
sudo nmcli con up eth0
# /etc/network/interfaces
auto eth0
iface eth0 inet static
address 192.168.1.50
netmask 255.255.255.0
gateway 192.168.1.1
dns-nameservers 8.8.8.8
Apply with `sudo ifdown eth0 && sudo ifup eth0`.
Automatic Configuration (DHCP)¶
Most of the time, a DHCP (Dynamic Host Configuration Protocol) server already on the network hands out an IP, subnet, gateway, and DNS servers automatically — no manual configuration needed at all.
Which tool is my distro actually using?
- Ubuntu Desktop/Server 18.04+ → netplan (typically with NetworkManager as the backend on Desktop, systemd-networkd on Server)
- Debian (classic) → ifupdown, unless changed
- Fedora / RHEL / CentOS → NetworkManager
- Arch, minimal server installs → often bare systemd-networkd
Not sure which one's actually active? Check for a running nmcli, or look for /etc/netplan/*.yaml, /etc/systemd/network/*.network, or /etc/network/interfaces to see what's actually configured.
DNS¶
DNS turns names into IP addresses, but Linux checks more than one source before it even asks a DNS server:
/etc/hosts— static, manually-defined name→IP mappings, checked first by default/etc/resolv.conf— lists the actual DNS server(s) to query (nameserver 8.8.8.8, for example)/etc/nsswitch.conf— controls the overall lookup order (hosts: files dnsis the common default, meaning/etc/hostsis checked before DNS)
dig example.com # detailed DNS query, shows the full response
host example.com # quick, simple lookup
nslookup example.com # older, still widely available lookup tool
Common Networking Commands¶
| Command | Purpose |
|---|---|
ping <host> |
Test basic reachability and round-trip latency |
traceroute <host> |
Show the path (hop by hop) packets take to a destination |
mtr <host> |
A continuously-updating combination of ping and traceroute |
ss -tulpn |
List listening TCP/UDP sockets, with the process using each one |
curl <url> |
Fetch a URL — the go-to tool for testing HTTP(S) connectivity |
wget <url> |
Download a file over HTTP(S)/FTP |
nmap <host> |
Scan a host for open ports and running services |
tcpdump -i eth0 |
Capture raw packets on an interface for inspection |
Common Networking Commands
ss vs. netstat?
ss (socket statistics) is the modern replacement for netstat — faster, and pulls its data directly from the kernel rather than parsing /proc. netstat still works on most systems, but ss is what you'll see recommended in current documentation.1
Firewalls¶
Linux firewalling happens in the kernel via netfilter, but you'll usually interact with it through a higher-level tool rather than netfilter directly:
iptables— the long-standing, rule-based classic (still widely deployed, especially on older systems)nftables— netfilter's modern replacement for iptables, with a cleaner syntaxufw(Uncomplicated Firewall) — a friendlier frontend over iptables/nftables, common on Ubuntu/Debianfirewalld— a dynamic, zone-based frontend common on Red Hat/Fedora/CentOS
sudo ufw status # check firewall status (Debian/Ubuntu)
sudo ufw allow 22/tcp # allow SSH
sudo firewall-cmd --state # check firewall status (RHEL/Fedora)
Useful Resources¶
- iproute2 — Linux Foundation wiki on the modern
ip/sstoolset - Netplan Documentation
- systemd-networkd Documentation
- IETF — RFC 1918: Address Allocation for Private Internets
-
Linux Foundation. (n.d.). iproute2. Linux Foundation Wiki. https://wiki.linuxfoundation.org/networking/iproute2 ↩↩
-
Rekhter, Y., Moskowitz, B., Karrenberg, D., de Groot, G. J., & Lear, E. (1996). Address allocation for private internets (RFC 1918). IETF. https://www.rfc-editor.org/rfc/rfc1918 ↩