The ip Command Explained: Addresses, Routes, Links, and Neighbours
ip is the Linux command for looking at and changing network configuration: which interfaces exist, what addresses they have, where traffic is routed, and which MAC address belongs to which neighbour. It comes from the iproute2 package and replaced the old ifconfig, route, and arp commands years ago.
If networking concepts are new, read Linux networking basics and IP addresses explained first.
How ip commands are structured
Every ip command follows the same shape:
ip [options] OBJECT COMMAND [arguments]
| Object | Short | What it manages |
|---|---|---|
link | l | Network interfaces themselves (up, down, MTU, MAC) |
address | a | IP addresses on interfaces |
route | r | The routing table |
neigh | n | Neighbour table (ARP for IPv4, NDP for IPv6) |
rule | ru | Policy routing rules |
netns | Network namespaces |
Commands are usually show (the default, so you can omit it), add, del, and set. Objects and commands can be abbreviated, which is why ip a and ip r work.
Two options make output far more readable:
ip -br a # brief: one line per interface
ip -c a # colour
ip -br -c a # both
Interfaces: ip link
ip link
ip -br link
# lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
# enp3s0 UP 3c:7c:3f:12:ab:cd <BROADCAST,MULTICAST,UP,LOWER_UP>
# wlp2s0 DOWN a4:34:d9:55:12:ef <NO-CARRIER,BROADCAST,MULTICAST,UP>
The flags tell you most of what you need. UP means the interface is administratively enabled; LOWER_UP means there is a physical link (a cable, or an associated Wi-Fi network). NO-CARRIER means the interface is up but nothing is connected.
sudo ip link set enp3s0 down
sudo ip link set enp3s0 up
sudo ip link set enp3s0 mtu 9000
Interface names like enp3s0 and wlp2s0 are “predictable names” based on hardware location, replacing the old eth0 scheme.
Addresses: ip addr
ip addr
ip -br addr
# lo UNKNOWN 127.0.0.1/8 ::1/128
# enp3s0 UP 192.168.1.42/24 fd00::42/64 fe80::3e7c:3fff:fe12:abcd/64
The /24 is the prefix length: the first 24 bits are the network, so every address from 192.168.1.0 to 192.168.1.255 is directly reachable. An interface can hold many addresses, which is normal for IPv6 and common for IPv4 on servers.
sudo ip addr add 192.168.1.50/24 dev enp3s0
sudo ip addr del 192.168.1.50/24 dev enp3s0
sudo ip addr flush dev enp3s0 # remove all addresses (careful over SSH)
fe80:: addresses are IPv6 link-local addresses that every interface gets automatically. Our IPv6 on Linux guide covers what the other IPv6 addresses mean.
Routes: ip route
ip route
# default via 192.168.1.1 dev enp3s0 proto dhcp metric 100
# 192.168.1.0/24 dev enp3s0 proto kernel scope link src 192.168.1.42
The first line is the default route: anything not matched by a more specific route goes to the gateway at 192.168.1.1. The second says the local subnet is reached directly on enp3s0.
The most useful routing command is ip route get, which asks the kernel exactly how it would reach an address:
ip route get 1.1.1.1
# 1.1.1.1 via 192.168.1.1 dev enp3s0 src 192.168.1.42
That answers “which interface and source address will this traffic use?”, which is the first question when a VPN, a second NIC, or Docker’s bridges are involved.
sudo ip route add 10.20.0.0/16 via 192.168.1.254
sudo ip route del 10.20.0.0/16
sudo ip route replace default via 192.168.1.1 dev enp3s0
IPv6 routes live in a separate table: ip -6 route.
Neighbours: ip neigh
ip neigh
# 192.168.1.1 dev enp3s0 lladdr 9c:53:22:aa:bb:cc REACHABLE
# 192.168.1.17 dev enp3s0 lladdr 00:11:32:de:ad:00 STALE
This is the mapping from IP addresses on your local network to MAC addresses, learned through ARP (IPv4) and neighbour discovery (IPv6). REACHABLE entries were recently confirmed; STALE ones will be re-checked on next use; FAILED means nothing answered, a useful clue that a host is down or on a different VLAN.
sudo ip neigh flush dev enp3s0
Other useful objects
Statistics per interface, including errors and drops:
ip -s link show enp3s0
Rising errors or dropped counters point at cabling, duplex, or driver problems rather than configuration.
Network namespaces, the isolation containers use for networking:
sudo ip netns add test
sudo ip netns exec test ip link
Our container networking guide and namespaces explainer cover how Docker and Podman use these.
Watching changes live:
ip monitor
This prints every address, link, and route change as it happens, which is excellent for debugging a network manager or VPN that keeps changing things.
ip changes are not permanent
Everything ip does changes the running kernel state. On reboot, or when NetworkManager or systemd-networkd reapplies its configuration, your changes are gone. That is useful for experiments and emergencies, but permanent configuration belongs to your network manager:
| Tool | Where it is used |
|---|---|
NetworkManager (nmcli) | Most desktops, Fedora, RHEL |
| netplan | Ubuntu servers (generates NetworkManager or networkd config) |
| systemd-networkd | Minimal servers, containers, Arch setups |
ifupdown (/etc/network/interfaces) | Older Debian installs |
Our guide to checking connections with ss and nmcli covers the NetworkManager side.
ifconfig to ip
| Old | New |
|---|---|
ifconfig | ip addr / ip -br a |
ifconfig eth0 up | ip link set eth0 up |
ifconfig eth0 192.168.1.5/24 | ip addr add 192.168.1.5/24 dev eth0 |
route -n | ip route |
route add default gw 192.168.1.1 | ip route add default via 192.168.1.1 |
arp -a | ip neigh |
netstat -i | ip -s link |
For finding which process is listening on a port, ss replaces netstat; see checking open ports. For a troubleshooting sequence that combines all of these, see network troubleshooting commands.
Frequently Asked Questions
What is the ip command in Linux?
ip is the standard command-line tool for viewing and changing network configuration on Linux, from the iproute2 package. It manages interfaces, IP addresses, routes, the ARP and neighbour table, policy routing rules, and network namespaces, replacing older tools like ifconfig, route and arp.
How do I show my IP address with ip?
Run ip addr, or its short form ip a. For a compact one-line-per-interface view, run ip -br a. To show only one interface, add dev followed by its name, for example ip addr show dev enp3s0.
Are changes made with ip permanent?
No. ip changes the running kernel configuration only, and everything is lost on reboot or when a network manager reconfigures the interface. Permanent settings belong in your network manager, such as NetworkManager with nmcli, systemd-networkd, or netplan.
Why was ifconfig replaced by ip?
ifconfig comes from the net-tools package, which stopped being actively developed years ago and does not support many newer kernel networking features such as multiple addresses per interface shown properly, policy routing, and namespaces. ip talks to the kernel through netlink and supports all of them.
How do I see the default gateway?
Run ip route, or ip r. The line beginning with default shows the gateway address and the interface used. ip route get followed by a destination address shows exactly which route and source address the kernel would use to reach it.
What does ip neigh show?
ip neigh shows the neighbour table, which maps IP addresses on the local network to hardware MAC addresses. It is the modern replacement for arp -a, and covers both IPv4 ARP entries and IPv6 neighbour discovery.