← Downloads

iproute2 6.13.0

Package v6.13.0 x86_64 TAR.XZ February 1, 2026

The modern Linux networking toolset: ip for addresses, routes, links, bridges, and VLANs, ss for sockets, and tc for traffic control. Replaces ifconfig, route, and netstat.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
kernel.org Releases Primary Global Download
iproute2 Git Global Download

iproute2 replaced the net-tools suite, and the replacements are not just renamed: they expose kernel features the old tools never could.

The mapping

OldNew
ifconfigip addr, ip link
routeip route
netstatss
arpip neigh
iptunnelip tunnel

ifconfig is not merely deprecated; it cannot show multiple addresses per interface correctly, and it has no concept of network namespaces, policy routing, or most of what a modern kernel does.

Everyday commands

ip -br addr                    # brief, readable
ip -c addr                     # colourised
ip route
ip -6 route
ip neigh
ip link set eth0 up

ss -tlnp                       # listening TCP sockets with processes
ss -tunap                      # everything, TCP and UDP
ss -s                          # summary statistics

ip -br addr is the one worth putting in muscle memory. It is what ifconfig should have printed.

ss -tlnp answers “what is listening on this machine,” which is the first question on any new server. Anything bound to 0.0.0.0 is reachable from your whole network.

Where it goes beyond the old tools

Network namespaces, which is what containers use:

ip netns list
sudo ip netns exec myns ip addr

Bridges and VLANs directly:

ip link add name br0 type bridge
ip link add link eth0 name eth0.10 type vlan id 10

Our VLANs and bridges guide covers those.

Policy routing, multiple routing tables selected by source address or mark, which route simply cannot express.

tc, the traffic control interface, covered in our traffic shaping guide.

Versioning

iproute2 releases track kernel versions, because the tools expose kernel netlink features. A version noticeably older than your kernel may not support newer options, which is the usual reason a documented flag is rejected.

ip -V

Verify Your Download

Source releases on kernel.org are published with GPG signatures. Every distribution packages it and it is installed by default.