Linux ip Command with Examples

When a server comes back from a reboot without network access, the first thing to check is which interfaces are up and which addresses they have. On modern Linux systems, you do that with the ip command. It is used to bring interfaces up or down, assign and remove addresses and routes, manage ARP cache, and much more.
This article explains how to use the ip command through practical examples and detailed explanations of the most common options.
Planning an IP scheme? Our interactive subnet calculator breaks any CIDR block into its network, broadcast, and usable host range.
How to Use the ip Command
The ip utility is part of the iproute2 package, which is installed on all modern Linux distributions.
The syntax for the ip command is as follows:
ip [OPTIONS] OBJECT { COMMAND | help }OBJECT is the object type you want to manage. The most frequently used objects are:
link(l) - Display and modify network interfaces.address(a) - Display and modify IP addresses.route(r) - Display and alter the routing table.neigh(n) - Display and manipulate neighbor objects (ARP table).
Each object can be written in full or abbreviated form. To display a list of commands and arguments for a given object, run ip OBJECT help.
OPTIONS change how the output looks or which address family is shown. The ones you will use most often are:
-4- Show only IPv4 information.-6- Show only IPv6 information.-br- Print a brief, one-line summary per interface.-c- Color the output.-s- Show statistics. Repeat it (-s -s) for more detail.-d- Show detailed information, such as the link type.-j- Print the output in JSON format.
When configuring network interfaces, you must run the commands as root or a user with sudo
privileges. Otherwise, the command will print RTNETLINK answers: Operation not permitted.
The configurations set with the ip command are not persistent. After a system restart, all changes are lost. To make changes permanent, you need to edit the distribution-specific network configuration files or add the commands to a startup script.
Displaying and Modifying IP Addresses
When operating with the addr object, commands take the following form:
ip addr [COMMAND] ADDRESS dev IFNAMEThe most frequently used commands of the addr object are show, add, and del.
Display Information about All IP Addresses
To display a list of all network interfaces and their associated IP addresses:
ip addr show1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 52:54:00:8c:62:44 brd ff:ff:ff:ff:ff:ff
inet 192.168.121.241/24 brd 192.168.121.255 scope global dynamic eth0
valid_lft 2900sec preferred_lft 2900sec
inet6 fe80::5054:ff:fe8c:6244/64 scope link proto kernel_ll
valid_lft forever preferred_lft foreverEach interface block starts with the index number and the interface name, followed by the flags in angle brackets. UP means the interface is enabled, and LOWER_UP means the physical link is up. The state field shows the operational state, and mtu is the largest packet size the interface can send.
The link/ether line shows the MAC address of the interface. Each inet line is an IPv4 address with its prefix length, and each inet6 line is an IPv6 address. The dynamic keyword marks a nonpermanent address. In this example, the IPv4 address was assigned by DHCP, but IPv6 addresses configured through router advertisements can also be dynamic. valid_lft shows how long the address remains valid, in seconds or as forever.
You will get the same output if you omit show and type ip addr, or use the shortest form, ip a. To display only IPv4 or IPv6 addresses, use ip -4 addr or ip -6 addr.
Display Addresses in Brief Format
On systems with several interfaces, the full output gets long. The -br option prints one line per interface with its name, state, and addresses:
ip -br alo UNKNOWN 127.0.0.1/8 ::1/128
eth0 UP 192.168.121.241/24 fe80::5054:ff:fe8c:6244/64The first column is the interface name, the second is the operational state, and the rest of the line lists the assigned addresses. The loopback interface always reports UNKNOWN, so you can ignore that state.
The same option works with the link object. Instead of addresses, ip -br link prints the MAC address and the interface flags:
ip -br linklo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
eth0 UP 52:54:00:8c:62:44 <BROADCAST,MULTICAST,UP,LOWER_UP>To make the output easier to scan in a terminal, add the -c option. Interface names, states, and addresses are printed in different colors:
ip -c -br aIf you need the data in a script, use -j to get JSON output:
ip -j -br a show lo[{"ifname":"lo","operstate":"UNKNOWN","addr_info":[{"local":"127.0.0.1","prefixlen":8},{"local":"::1","prefixlen":128}]}]Display Information about a Single Interface
To get information about a specific network interface, use ip addr show dev followed by the device name:
ip addr show dev eth0Assign an IP Address to an Interface
To assign an IP address to an interface:
ip addr add ADDRESS dev IFNAMEWhere IFNAME is the interface name and ADDRESS is the IP address with its prefix length.
To add address 192.168.121.45/24 to device eth0:
sudo ip address add 192.168.121.45/24 dev eth0On success, the command produces no output. If the interface does not exist, you will get Cannot find device "eth0". If the address is already set on the interface, the command fails with Error: ipv4: Address already assigned.
Assign Multiple IP Addresses to the Same Interface
With ip, you can assign multiple addresses to the same interface. To add two more addresses to eth0:
sudo ip address add 192.168.121.46/24 dev eth0
sudo ip address add 192.168.121.47/24 dev eth0To confirm the IPs are assigned:
ip -4 addr show dev eth02: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
inet 192.168.121.241/24 brd 192.168.121.255 scope global dynamic eth0
valid_lft 3515sec preferred_lft 3515sec
inet 192.168.121.45/24 scope global secondary eth0
valid_lft forever preferred_lft forever
inet 192.168.121.46/24 scope global secondary eth0
valid_lft forever preferred_lft forever
inet 192.168.121.47/24 scope global secondary eth0
valid_lft forever preferred_lft foreverThe first address in a subnet is the primary one. Every address you add later in the same subnet is marked as secondary.
Remove an IP Address from an Interface
To remove an IP address from an interface:
ip addr del ADDRESS dev IFNAMETo remove address 192.168.121.45/24 from device eth0:
sudo ip address del 192.168.121.45/24 dev eth0ip addr flush also removes the address you are connected through. Do not run it on the interface that carries your SSH session unless you have console access to the machine.To remove all IP addresses from an interface at once, use flush:
sudo ip addr flush dev eth0Displaying and Modifying Network Interfaces
To manage and view the state of network interfaces, use the link object. The most commonly used commands are show, set, add, and del.
Display Information about Network Interfaces
To display a list of all network interfaces:
ip link show1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP mode DEFAULT group default qlen 1000
link/ether 52:54:00:8c:62:44 brd ff:ff:ff:ff:ff:ffUnlike ip addr show, ip link show does not print IP address information.
To query a specific interface:
ip link show dev eth02: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP mode DEFAULT group default qlen 1000
link/ether 52:54:00:8c:62:44 brd ff:ff:ff:ff:ff:ffBring an Interface Up or Down
To bring interfaces up or down, use ip link set dev followed by the device name and state:
ip link set dev DEVICE { up | down }To bring eth0 online:
sudo ip link set eth0 upTo bring it offline:
sudo ip link set eth0 downChange the MTU of an Interface
The set command also changes link settings such as the MTU. To set the MTU of eth0 to 9000 bytes:
sudo ip link set dev eth0 mtu 9000Larger MTU values (jumbo frames) work only when the network card, the switch, and the other host all support them. Otherwise, large packets are dropped.
Display Interface Statistics
To view packet and error statistics for an interface, use the -s flag:
ip -s link show dev eth02: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP mode DEFAULT group default qlen 1000
link/ether 52:54:00:8c:62:44 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped missed mcast
1923498 8438 0 0 0 204
TX: bytes packets errors dropped carrier collsns
842103 5565 0 0 0 0The RX lines show received traffic, and the TX lines show transmitted traffic. If the errors or dropped counters keep growing, investigate further. Errors can indicate problems with the cable, driver, or network card, while drops can also result from resource shortages or unsupported protocols. These counters alone do not identify the cause.
Displaying and Altering the Routing Table
To assign, remove, and display kernel routing table entries, use the route object.
Display the Routing Table
To list all kernel route entries:
ip route listdefault via 192.168.121.1 dev eth0 proto dhcp src 192.168.121.241 metric 100
192.168.121.0/24 dev eth0 proto kernel scope link src 192.168.121.241
192.168.121.1 dev eth0 proto dhcp scope link src 192.168.121.241 metric 100The first line is the default route. Traffic for any destination without a more specific route goes to the gateway 192.168.121.1 through eth0.
The proto field shows who added the route. proto dhcp means the route came from the DHCP client, and proto kernel means the kernel created it when the address was assigned. src is the source address for outgoing packets, and metric is the route priority. Within a routing table, the kernel first chooses the longest matching destination prefix. When routes have the same destination prefix, the one with the lower metric is preferred.
To display routing for a specific network:
ip route list 172.17.0.0/16172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdownFind Which Route a Packet Takes
To see which route the kernel uses for a specific destination, use ip route get:
ip route get 1.1.1.11.1.1.1 via 192.168.121.1 dev eth0 src 192.168.121.241 uid 1000
cacheThe output shows the gateway, the outgoing interface, and the source address the kernel would use for that destination. This is useful on hosts with several interfaces or a VPN connection. On those systems, it is not always obvious which path a connection takes.
Add a New Route
To add a route to the 10.10.0.0/24 network via the gateway at 192.168.121.1:
sudo ip route add 10.10.0.0/24 via 192.168.121.1To add a route to a network that is reachable directly on device eth0:
sudo ip route add 10.20.0.0/24 dev eth0To add a default route via the gateway 192.168.121.1 on device eth0:
sudo ip route add default via 192.168.121.1 dev eth0Delete a Route
To delete an entry from the routing table, use the route del command with the same syntax as route add.
To delete a specific route:
sudo ip route del 10.10.0.0/24 via 192.168.121.1To delete the default route:
sudo ip route del defaultDisplaying and Manipulating the ARP Table
The neigh object manages the neighbor (ARP) table, which maps IP addresses to MAC addresses on the local network.
To display the current ARP table:
ip neigh show192.168.121.1 dev eth0 lladdr 52:54:00:12:35:02 REACHABLE
192.168.121.10 dev eth0 lladdr 52:54:00:9a:41:af STALEEach line shows the neighbor IP address, the interface, and the MAC address after lladdr. REACHABLE means the entry was confirmed recently. STALE means the entry has not been used for a while, and the kernel checks it again the next time it sends traffic to that address.
To add a static ARP entry:
sudo ip neigh add 192.168.121.50 lladdr 00:11:22:33:44:55 dev eth0Static entries do not expire and are shown with the PERMANENT state.
To delete an ARP entry:
sudo ip neigh del 192.168.121.50 dev eth0To flush dynamic ARP entries for an interface:
sudo ip neigh flush dev eth0By default, flush leaves entries in the PERMANENT and NOARP states intact.
Quick Reference
For a printable quick reference, see the IP command cheatsheet .
| Command | Description |
|---|---|
ip a | Show all IP addresses |
ip -br a | Show a one-line summary per interface |
ip addr show dev eth0 | Show addresses for one interface |
ip addr add IP/PREFIX dev eth0 | Assign an IP address |
ip addr del IP/PREFIX dev eth0 | Remove an IP address |
ip addr flush dev eth0 | Remove all addresses from an interface |
ip link show | Show all interfaces |
ip link set eth0 up | Bring interface up |
ip link set eth0 down | Bring interface down |
ip link set dev eth0 mtu 9000 | Change the MTU |
ip -s link show dev eth0 | Show interface statistics |
ip route list | Show routing table |
ip route get IP | Show the route used for a destination |
ip route add default via GW dev eth0 | Add default route |
ip route del default | Delete default route |
ip neigh show | Show ARP table |
ip neigh flush dev eth0 | Flush ARP entries for interface |
Troubleshooting
“RTNETLINK answers: Operation not permitted”
The command requires root privileges. Prefix it with sudo: sudo ip link set eth0 up.
“Cannot find device”
The interface name is wrong or the interface does not exist. List available interfaces with ip -br link to find the correct name. Modern systems use names like ens3, enp0s1, or wlp2s0 instead of eth0.
“Error: ipv4: Address already assigned.”
The address is already set on that interface. Check the current addresses with ip -br a. To change the prefix length, delete the address first with ip addr del, then add it again.
ip route add fails with “RTNETLINK answers: File exists”
A route for the same destination already exists. Delete the existing route first with ip route del DESTINATION, then re-add it.
Changes lost after reboot
The ip command applies changes only to the running kernel state. To make them persistent, add the configuration to your distribution’s network configuration: Netplan
on Ubuntu, NetworkManager with nmcli
, systemd-networkd, or /etc/network/interfaces on Debian.
FAQ
What does ip a do?ip a is the short form of ip address show. It lists every network interface with its IPv4 and IPv6 addresses. The ip command accepts abbreviated object names, so ip a, ip addr, and ip address all run the same command.
What is the difference between ip and ifconfig?ifconfig is part of the older net-tools package and is deprecated on most modern Linux distributions. ip from the iproute2 package is the replacement. It supports more features, has a consistent syntax across all network objects, and is actively maintained.
How do I make ip changes persistent across reboots?
The ip command modifies the running kernel state only. To persist changes, configure your network manager: systemd-networkd (edit files in /etc/systemd/network/), NetworkManager (use nmcli or connection files), or the distro-specific interface configuration.
How do I find my server’s IP address?
Run ip addr show and look for inet lines. The loopback address 127.0.0.1 is the local machine; any other inet address on an active interface is your network IP. For other methods, including how to find your public IP, see How to Find Your IP Address in Linux
.
What does the /24 mean in an IP address like 192.168.1.1/24?
The /24 is the prefix length (CIDR notation). It defines the subnet mask: /24 means the first 24 bits are the network portion, equivalent to a 255.255.255.0 netmask. This tells the system which addresses are on the local network. For prefix-to-mask conversion and subnet math, see CIDR Notation and Subnetting Explained
.
Can I use ip to monitor network traffic?
The ip -s link show command shows basic packet and error counters. For detailed traffic monitoring, use dedicated tools like ss
, netstat
, iftop, or tcpdump
.
Conclusion
The ip command replaces the older ifconfig and route commands on modern Linux systems and manages addresses, interfaces, routes, and the ARP table with one consistent syntax. For more details on available options, run man ip or ip OBJECT help.
Linuxize Weekly Newsletter
A quick weekly roundup of new tutorials, news, and tips.
About the authors

Dejan Panovski
Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.
View author page