iproute2 6.13.0
The modern Linux networking toolset: ip for addresses, routes, links, bridges, and VLANs, ss for sockets, and tc for traffic control. Replaces ifconfig, route, and netstat.
Download TAR.XZ Project website ↗Download Mirrors
iproute2 replaced the net-tools suite, and the replacements are not just renamed: they expose kernel features the old tools never could.
The mapping
| Old | New |
|---|---|
ifconfig | ip addr, ip link |
route | ip route |
netstat | ss |
arp | ip neigh |
iptunnel | ip tunnel |
ifconfig is not merely deprecated; it cannot show multiple addresses per interface correctly, and it has no concept of network namespaces, policy routing, or most of what a modern kernel does.
Everyday commands
ip -br addr # brief, readable
ip -c addr # colourised
ip route
ip -6 route
ip neigh
ip link set eth0 up
ss -tlnp # listening TCP sockets with processes
ss -tunap # everything, TCP and UDP
ss -s # summary statistics
ip -br addr is the one worth putting in muscle memory. It is what ifconfig should have printed.
ss -tlnp answers “what is listening on this machine,” which is the first question on any new server. Anything bound to 0.0.0.0 is reachable from your whole network.
Where it goes beyond the old tools
Network namespaces, which is what containers use:
ip netns list
sudo ip netns exec myns ip addr
Bridges and VLANs directly:
ip link add name br0 type bridge
ip link add link eth0 name eth0.10 type vlan id 10
Our VLANs and bridges guide covers those.
Policy routing, multiple routing tables selected by source address or mark, which route simply cannot express.
tc, the traffic control interface, covered in our traffic shaping guide.
Versioning
iproute2 releases track kernel versions, because the tools expose kernel netlink features. A version noticeably older than your kernel may not support newer options, which is the usual reason a documented flag is rejected.
ip -V
Verify Your Download
Source releases on kernel.org are published with GPG signatures. Every distribution packages it and it is installed by default.