Network Configuration
Modern Linux systems use the ip command (from the iproute2 package) for network configuration, replacing the older ifconfig. Most desktop distributions also use NetworkManager for automatic configuration through a graphical interface.
Viewing Network Interfaces
# Show all network interfaces with IP addresses
ip addr show
ip a # shorthand
# Show a specific interface
ip addr show eth0
# Show only IPv4 addresses
ip -4 addr show
# Show link layer (MAC addresses, state)
ip link show
# Show interfaces that are UP
ip link show up
Configuring IP Addresses
# Add an IP address to an interface
sudo ip addr add 192.168.1.100/24 dev eth0
# Remove an IP address
sudo ip addr del 192.168.1.100/24 dev eth0
# Bring an interface up
sudo ip link set eth0 up
# Bring an interface down
sudo ip link set eth0 down
# Change MTU (Maximum Transmission Unit)
sudo ip link set eth0 mtu 9000
Temporary vs Persistent Configuration
Changes made with the ip command are temporary and lost after reboot. For persistent configuration, use your distribution's networking system: Netplan (/etc/netplan/) on Ubuntu, NetworkManager (nmcli/nmtui) on most desktops, or systemd-networkd for server setups.
Persistent Configuration with Netplan (Ubuntu)
# /etc/netplan/01-config.yaml
network:
version: 2
renderer: networkd
ethernets:
eth0:
addresses:
- 192.168.1.100/24
routes:
- to: default
via: 192.168.1.1
nameservers:
addresses:
- 8.8.8.8
- 8.8.4.4
# Apply netplan changes
sudo netplan apply
DNS Configuration
DNS (Domain Name System) translates domain names into IP addresses. Linux resolves names using the configuration in /etc/resolv.conf or through systemd-resolved.
# View current DNS configuration
cat /etc/resolv.conf
# Check systemd-resolved status
resolvectl status
# Test DNS resolution
nslookup example.com
dig example.com
host example.com
# Detailed DNS query
dig +trace example.com
# Local hostname resolution
cat /etc/hosts
The /etc/hosts File
The /etc/hosts file provides static hostname-to-IP mappings that take priority over DNS. It is useful for local development, blocking domains, or defining hostnames for local network machines:
# /etc/hosts
127.0.0.1 localhost
127.0.1.1 mycomputer
192.168.1.50 fileserver.local fileserver
192.168.1.51 devdb.local
Routing
The routing table determines how network traffic is directed. The kernel uses it to decide where to send each packet based on its destination address.
# View the routing table
ip route show
ip r # shorthand
# View only default gateway
ip route show default
# Add a default gateway
sudo ip route add default via 192.168.1.1
# Add a route to a specific network
sudo ip route add 10.0.0.0/8 via 192.168.1.254
# Delete a route
sudo ip route del 10.0.0.0/8
# Trace the route packets take to a destination
traceroute example.com
tracepath example.com
Firewall Management
UFW (Uncomplicated Firewall)
UFW is a user-friendly frontend for iptables, available by default on Ubuntu and many other distributions:
# Enable the firewall
sudo ufw enable
# Check firewall status and rules
sudo ufw status verbose
# Allow incoming SSH (essential before enabling on remote servers!)
sudo ufw allow ssh
sudo ufw allow 22/tcp
# Allow a specific port
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# Allow a port range
sudo ufw allow 8000:8080/tcp
# Allow from a specific IP
sudo ufw allow from 192.168.1.0/24
# Allow from specific IP to specific port
sudo ufw allow from 10.0.0.5 to any port 3306
# Deny incoming traffic on a port
sudo ufw deny 3306/tcp
# Delete a rule
sudo ufw delete allow 80/tcp
# Reset all rules
sudo ufw reset
# Set default policies
sudo ufw default deny incoming
sudo ufw default allow outgoing
iptables (Advanced)
iptables is the traditional Linux firewall tool that provides granular control over packet filtering:
# List all rules
sudo iptables -L -n -v
# Allow established connections
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
# Allow SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# Allow HTTP and HTTPS
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT
# Allow loopback
sudo iptables -A INPUT -i lo -j ACCEPT
# Drop all other incoming traffic
sudo iptables -A INPUT -j DROP
# Save rules (Debian/Ubuntu)
sudo iptables-save > /etc/iptables/rules.v4
SSH (Secure Shell)
SSH is the standard protocol for secure remote access to Linux systems. It provides encrypted communication between client and server.
# Connect to a remote server
ssh [email protected]
ssh [email protected]
# Connect on a non-standard port
ssh -p 2222 [email protected]
# Copy files to a remote server
scp file.txt user@server:/home/user/
scp -r directory/ user@server:/home/user/
# Copy files from a remote server
scp user@server:/var/log/syslog ./
# Generate an SSH key pair
ssh-keygen -t ed25519 -C "[email protected]"
# Copy public key to a server (enables passwordless login)
ssh-copy-id user@server
# SSH tunneling (port forwarding)
ssh -L 8080:localhost:80 user@server # Local forwarding
ssh -R 9090:localhost:3000 user@server # Remote forwarding
Network Troubleshooting
# Test connectivity
ping google.com
ping -c 4 192.168.1.1 # send exactly 4 packets
# Check if a port is open
nc -zv server.com 80
nc -zv server.com 22
# Show active network connections
ss -tuln # listening sockets
ss -tupn # established connections with process info
# Show all connections with process names
sudo ss -tulnp
# DNS lookup
dig example.com
nslookup example.com
# Trace route to destination
traceroute example.com
mtr example.com # interactive (combines ping + traceroute)
# Capture network packets (advanced)
sudo tcpdump -i eth0 port 80
sudo tcpdump -i any -c 100 -w capture.pcap
# Test download speed
wget -O /dev/null http://speedtest.tele2.net/10MB.zip
# Show network interface statistics
ip -s link show eth0
# Show ARP table (IP to MAC mappings)
ip neigh show
NetworkManager CLI (nmcli)
For systems using NetworkManager, nmcli provides comprehensive network management from the terminal:
# Show all connections
nmcli connection show
# Show active connections
nmcli connection show --active
# Show device status
nmcli device status
# Connect to a Wi-Fi network
nmcli device wifi connect "NetworkName" password "password123"
# List available Wi-Fi networks
nmcli device wifi list
# Create a static IP connection
nmcli connection add type ethernet con-name "static-eth" ifname eth0 \
ip4 192.168.1.100/24 gw4 192.168.1.1
# Set DNS servers
nmcli connection modify "static-eth" ipv4.dns "8.8.8.8 8.8.4.4"
# Bring a connection up/down
nmcli connection up "static-eth"
nmcli connection down "static-eth"
# Interactive text UI
nmtui
Next Step
With networking knowledge under your belt, learn how to automate tasks with our Shell Scripting guide, or secure your network setup with Security Basics.