Linux Networking Basics
Networking on Linux is built around a small set of concepts that appear everywhere: interfaces, addresses, routes, and name resolution. Once these are clear, the tools and configuration files that manage them all follow the same logic.
Network interfaces
A network interface is the kernel object that connects a Linux system to a network. Every interface has a name, a MAC address (for physical interfaces), and can be assigned one or more IP addresses.
# List all interfaces with addresses
ip addr show
ip addr # short form
# Show a specific interface
ip addr show eth0
# Show only IPv4 addresses
ip -4 addr
# Show only IPv6 addresses
ip -6 addr
# List interfaces without address details
ip link show
# Show interface statistics (bytes, packets, errors)
ip -s link show eth0
Common interface names:
lo— loopback, always 127.0.0.1, used for local inter-process communicationeth0,ens3,enp3s0— Ethernet (the naming depends on the distribution and driver)wlan0,wlp2s0— Wi-Fidocker0,br-*— virtual bridge interfaces created by Dockertun0,wg0— VPN tunnel interfaces
IP addresses and subnet masks
Every interface on a network needs an IP address and a subnet mask. The subnet mask defines which part of the address is the network portion and which is the host portion.
# CIDR notation: address/prefix-length
# 192.168.1.50/24 means subnet 192.168.1.0, 256 addresses, mask 255.255.255.0
# Add a static IP to an interface (temporary, lost on reboot)
sudo ip addr add 192.168.1.100/24 dev eth0
# Remove an IP from an interface
sudo ip addr del 192.168.1.100/24 dev eth0
# Bring an interface up or down
sudo ip link set eth0 up
sudo ip link set eth0 down
Persistent IP configuration is handled by the network manager, not by ip commands directly:
# NetworkManager (Ubuntu Desktop, Fedora)
nmcli connection show
nmcli device status
nmcli con mod "Wired connection 1" ipv4.addresses 192.168.1.100/24
nmcli con mod "Wired connection 1" ipv4.gateway 192.168.1.1
nmcli con mod "Wired connection 1" ipv4.method manual
nmcli con up "Wired connection 1"
# systemd-networkd (Ubuntu Server, minimal installs)
# Configuration in /etc/systemd/network/*.network
# Netplan (Ubuntu 17.10+)
cat /etc/netplan/01-netcfg.yaml
sudo netplan apply
Routing
The routing table tells Linux where to send packets. Each entry maps a destination network to a next-hop address or interface.
# Show the routing table
ip route show
ip route # short form
# Typical output:
# default via 192.168.1.1 dev eth0 proto dhcp src 192.168.1.50 metric 100
# 192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.50
# The "default" entry is the default gateway -- where non-local traffic goes
# The "192.168.1.0/24" entry means traffic to that subnet goes directly out eth0
# Add a static route
sudo ip route add 10.0.0.0/8 via 192.168.1.254
# Delete a route
sudo ip route del 10.0.0.0/8
# Change the default gateway
sudo ip route replace default via 192.168.1.1 dev eth0
# Show which route would be used to reach an address
ip route get 8.8.8.8
DNS resolution
When you type a hostname, Linux needs to translate it to an IP address. The resolution order is configured in /etc/nsswitch.conf (typically: /etc/hosts first, then DNS).
# /etc/hosts: static local entries
cat /etc/hosts
# 127.0.0.1 localhost
# 192.168.1.10 myserver myserver.local
# DNS resolver configuration
cat /etc/resolv.conf
# nameserver 1.1.1.1
# nameserver 8.8.8.8
# search home.local
# On systemd systems, check the active DNS config
resolvectl status
resolvectl dns
Checking connectivity
# Basic reachability test
ping 8.8.8.8 # ICMP echo to Google DNS
ping -c 4 google.com # send exactly 4 packets
ping -i 0.2 -c 10 192.168.1.1 # fast ping: 5 per second
# Trace the path to a host
traceroute google.com
traceroute -n 8.8.8.8 # no DNS lookups, faster
mtr 8.8.8.8 # live, updating traceroute
# Test TCP connectivity (is a port open?)
nc -zv google.com 443 # netcat port check
curl -v --max-time 5 https://google.com # full HTTP test
telnet google.com 80 # older method, still common
Checking what is on the network
# Show ARP table (MAC to IP mappings for local network)
ip neigh show
arp -n # older command, same info
# Scan the local network for hosts (requires nmap)
sudo nmap -sn 192.168.1.0/24
# Show your network's DNS name
hostname -f # fully qualified hostname
hostname -I # all IP addresses of this machine
Key network configuration files
# Hosts file: static name-to-IP mappings
/etc/hosts
# DNS resolver config (may be managed by systemd-resolved)
/etc/resolv.conf
# NSS configuration: resolution order
/etc/nsswitch.conf
# Network interface config (distribution-dependent)
/etc/netplan/*.yaml # Ubuntu (Netplan)
/etc/systemd/network/*.network # systemd-networkd
/etc/NetworkManager/system-connections/ # NetworkManager
/etc/network/interfaces # Debian legacy
# Kernel network parameters
/proc/sys/net/ipv4/
/proc/sys/net/ipv6/
sysctl -a | grep net.ipv4 # show all IPv4 parameters
The TCP/IP layer model in practice
When a Linux machine sends a packet:
- Application layer: a program calls
connect()with a hostname and port - Transport layer: the kernel TCP/UDP stack adds source/destination port numbers
- Network layer: the kernel IP stack looks up the route, adds IP source/destination
- Link layer: the kernel ARP-resolves the next-hop MAC address and puts the packet on the wire
Each of these layers has corresponding tools: ss for transport, ip for network, ip neigh and tcpdump for the link layer.
# See active TCP connections (transport layer)
ss -tnp
# See routing decisions (network layer)
ip route get 8.8.8.8
# Capture raw packets (link layer and above)
sudo tcpdump -i eth0 -n
sudo tcpdump -i eth0 port 80 -n
Understanding which layer a problem lives in narrows down which tool to use and which configuration to check.
Frequently Asked Questions
How do I see my IP address on Linux?
Run ip addr show to see all network interfaces and their IP addresses. The output lists each interface with its IPv4 (inet) and IPv6 (inet6) addresses and subnet masks. For a shorter output showing just the IP addresses, use ip addr | grep inet. The older ifconfig command from the net-tools package does the same thing but is deprecated on modern distributions.
What is a network interface in Linux?
A network interface is the abstraction through which Linux sends and receives network traffic. Physical interfaces correspond to hardware (eth0 or ens3 for Ethernet, wlan0 for Wi-Fi). Virtual interfaces include lo (the loopback interface, always 127.0.0.1), docker0 and similar bridge interfaces created by container runtimes, and VPN tunnel interfaces like tun0. Each interface has a name, a MAC address, and can have one or more IP addresses assigned.
What is the difference between ip and ifconfig?
ip is the modern tool from the iproute2 package and is the standard on all current Linux distributions. It handles addresses, routes, neighbour tables, and network namespaces in a unified interface. ifconfig is from the older net-tools package, is no longer maintained, and is absent from minimal installs of many distributions. Use ip for new work. ifconfig may still appear in older documentation and scripts.
What is a default gateway in Linux networking?
The default gateway is the IP address of the router that handles traffic destined for addresses outside the local network. When Linux needs to send a packet to an address that does not match any directly connected subnet, it forwards the packet to the default gateway. You can see the default gateway with ip route show — it appears as the route with destination 0.0.0.0/0 or default. Setting an incorrect or missing default gateway is one of the most common causes of a machine that can ping local hosts but cannot reach the internet.
How does Linux resolve hostnames to IP addresses?
Linux uses the Name Service Switch (NSS) framework, configured in /etc/nsswitch.conf, to determine the order of hostname resolution. The default order is typically: check /etc/hosts first (local static entries), then query DNS. DNS resolver configuration lives in /etc/resolv.conf, which lists the nameserver IPs to query. On systemd systems, systemd-resolved handles DNS queries and caching, and /etc/resolv.conf is often a symlink to its stub resolver.
What is the loopback interface?
The loopback interface (lo) is a virtual interface that routes traffic back to the same machine. Its IPv4 address is 127.0.0.1 (with the full 127.0.0.0/8 range available) and its IPv6 address is ::1. Any packet sent to 127.0.0.1 is received by the same machine without going through any physical network. The loopback is used for inter-process communication on the same host: a web server binding to 127.0.0.1 is only accessible locally, not from the network.