Skip to content

Network Configuration

Changes made with ip take effect immediately and vanish at reboot. Persistent network configuration belongs to a network manager: Netplan on Ubuntu, NetworkManager on RHEL. Find out which one owns the interface before you change anything, or your change will be silently overwritten.

What You'll Learn

  • How to inspect interfaces, addresses, routes, and link health with ip
  • Which tool owns network configuration on Ubuntu, RHEL, and cloud images
  • How to set a static address, routes, and DNS servers with Netplan and with nmcli
  • How to set the hostname so it survives reboots and cloud-init
  • How to change the network over SSH without locking yourself out

Mental Model

The kernel holds the live network state: interfaces, addresses, and routes. ip reads and edits that state directly. A network manager reads configuration files at boot and whenever you apply them, and writes that state for you. Change the files and apply them; use ip to look, and to make temporary changes while testing.

System Configuration files Applied by
Ubuntu Server 24.04 /etc/netplan/*.yaml Netplan, which generates config for systemd-networkd
Ubuntu Desktop /etc/netplan/*.yaml, or set in the GUI Netplan and NetworkManager
RHEL 9, Rocky, AlmaLinux /etc/NetworkManager/system-connections/*.nmconnection NetworkManager (nmcli, nmtui)
Cloud images Generated by cloud-init on first boot cloud-init, then the system's network manager

Inspect the Network

ip -br link                       # interfaces and whether they're UP
ip -br addr                       # addresses per interface
ip route                          # routing table; "default via" is the gateway
ip route get 10.20.4.15           # the exact route and source address for one destination
ip -s link show ens5              # packet, error, and drop counters
ethtool ens5 | grep -E 'Speed|Duplex|Link detected'
$ ip -br addr
lo               UNKNOWN        127.0.0.1/8 ::1/128
ens5             UP             10.0.1.20/24 fe80::8ff:fe12:3456/64

Interface names describe where the device is attached: ens5, enp0s3, and eno1 are typical. Some clouds still use eth0. Use the name your system shows; never assume eth0.

Which network manager is active:

networkctl list                   # systemd-networkd: interfaces it manages
nmcli device status               # NetworkManager: devices and their connections
ls /etc/netplan/                  # Netplan files, if any

Temporary Changes With ip

Useful for testing. Everything here is lost at reboot or when the network manager reapplies its configuration:

sudo ip addr add 10.0.1.21/24 dev ens5          # add a second address
sudo ip route add 10.20.0.0/16 via 10.0.1.254   # add a route
sudo ip link set ens5 mtu 9001                  # change the MTU
sudo ip addr del 10.0.1.21/24 dev ens5          # undo

Ubuntu: Netplan

A static address, a default gateway, an extra route, and DNS servers:

/etc/netplan/60-static.yaml
network:
  version: 2
  ethernets:
    ens5:
      dhcp4: false
      addresses:
        - 10.0.1.20/24
      routes:
        - to: default
          via: 10.0.1.1
        - to: 10.20.0.0/16
          via: 10.0.1.254
      nameservers:
        addresses: [10.0.0.2, 10.0.0.3]
        search: [example.internal]
sudo chmod 600 /etc/netplan/60-static.yaml   # Netplan warns if others can read it
sudo netplan generate                        # validate the YAML without applying it
sudo netplan try                             # apply, and roll back after 120 s unless you confirm
sudo netplan apply                           # apply without the safety net
netplan status                               # what's applied, per interface

netplan try is the safe way to change networking over SSH. If the change cuts you off, you can't press Enter to confirm, and the old configuration comes back on its own.

Older guides use gateway4:. It's deprecated; use a routes: entry with to: default. Netplan also configures bonds, bridges, and VLANs (bonds:, bridges:, vlans:) in the same file.

Stop cloud-init from overwriting it

On cloud images, cloud-init writes /etc/netplan/50-cloud-init.yaml at boot. If you manage networking yourself, tell cloud-init to stop:

/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg
network: {config: disabled}

RHEL Family: NetworkManager and nmcli

NetworkManager stores each configuration as a connection bound to a device. Find the connection name first; it's often not the interface name:

nmcli connection show
# NAME         UUID                                  TYPE      DEVICE
# System eth0  5fb06bd0-0bb0-7ffb-45f1-d6edd65f3e03  ethernet  eth0

Set a static address in one command, then reactivate the connection:

sudo nmcli connection modify "System eth0" \
  ipv4.method manual \
  ipv4.addresses 10.0.1.20/24 \
  ipv4.gateway 10.0.1.1 \
  ipv4.dns "10.0.0.2 10.0.0.3" \
  ipv4.dns-search example.internal
sudo nmcli connection up "System eth0"
sudo nmcli connection modify "System eth0" +ipv4.routes "10.20.0.0/16 10.0.1.254"   # add a route
nmcli -f ipv4 connection show "System eth0"          # review the settings
cat /etc/NetworkManager/system-connections/*.nmconnection   # the stored file (needs root)
sudo nmtui                                           # a text menu, if you prefer

RHEL 9 stores connections as keyfiles in /etc/NetworkManager/system-connections/. The older /etc/sysconfig/network-scripts/ifcfg-* files are deprecated; convert any you still have with nmcli connection migrate.

Run modify and up together on one command line when working over SSH. If the new address is wrong, the session drops either way, but the change finishes instead of stopping halfway. Have console access ready before changing the interface you're connected through.

DNS Resolution

Set DNS servers in the network configuration, as above, not in /etc/resolv.conf. On Ubuntu that file points to the local systemd-resolved stub (127.0.0.53) and is managed for you; edits are overwritten.

resolvectl status                 # upstream servers per interface (Ubuntu)
cat /etc/resolv.conf              # what applications read
getent hosts db.example.internal  # resolve exactly as applications do, including /etc/hosts

DNS explains the resolution path and how to debug it with dig.

Hostname

sudo hostnamectl set-hostname web01.example.internal
hostnamectl                       # static hostname, OS, kernel, virtualization

Add the name to /etc/hosts so the machine can always resolve itself, even without DNS:

/etc/hosts
127.0.0.1   localhost
127.0.1.1   web01.example.internal web01

On cloud instances, cloud-init may reset the hostname at boot. Set preserve_hostname: true in a file under /etc/cloud/cloud.cfg.d/ to keep yours.

Cloud Instances

On AWS, Azure, and Google Cloud, the platform assigns addresses and serves them over DHCP. Leave the primary interface on DHCP:

  • To add a private address, assign a secondary IP to the network interface through the cloud API first. Some images configure it automatically; others need it added to Netplan or nmcli as well.
  • A static address that doesn't match what the platform assigned stops traffic: the cloud network drops packets from addresses it didn't assign.
  • Firewalls are usually security groups or network rules outside the instance; check them as well as the host firewall described in Users, sudo, and SSH Hardening.

Troubleshooting

Symptom Check Likely cause
Interface DOWN or NO-CARRIER ip -br link, ethtool ens5 Cable, virtual NIC detached, or interface disabled in config
No IPv4 address journalctl -u systemd-networkd or journalctl -u NetworkManager DHCP failed, or a static config has a typo
Local network works, internet doesn't ip route, ip route get 1.1.1.1 Missing or wrong default route
IP works, names don't resolvectl status, getent hosts No DNS servers configured, or wrong search domain
Connectivity drops in and out ip -s link (rising errors), sudo arping -D -I ens5 10.0.1.20 A bad link, or another host using the same address
Config "doesn't stick" after reboot ls /etc/netplan/, cloud-init logs Change made with ip only, or cloud-init regenerated the file

For problems beyond the host itself, such as routing, firewalls, ports, and TLS, use the Network Troubleshooting Toolkit.

Common Mistakes

  • Making a change with ip and losing it at the next reboot.
  • Editing /etc/resolv.conf directly on a system where systemd-resolved or NetworkManager manages it.
  • Running netplan apply over SSH instead of netplan try.
  • Assigning a static IP to a cloud instance that doesn't match the address the platform gave it.
  • Editing the file cloud-init generates, then losing the change at the next boot.
  • Running nmcli connection modify and forgetting connection up, so nothing changes until the next restart.

Interview Questions

  • How do you find which tool manages networking on a Linux server?
  • How would you set a static IP on Ubuntu 24.04 over SSH without risking a lockout?
  • Why might a network change disappear after a reboot?
  • Where should DNS servers be configured on a modern Ubuntu system, and why not in /etc/resolv.conf?
  • What does ip route get tell you that ip route doesn't?

Next

You've finished Linux. Continue to Networking, or put these commands into scripts with Shell Scripting.