The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show concise addressesip -brief address showView examples
Export routes as JSONip -json route show table allView examples
Resolve an IPv4 pathip route get 203.0.113.10 from 192.0.2.20View examples
Resolve an IPv6 pathip -6 route get 2001:db8:2::10 from 2001:db8:1::20View examples
Show the main tableip route show table mainView examples
Replace a route idempotentlysudo ip route replace 198.51.100.0/24 via 192.0.2.1 dev \ eth0 metric 100View examples
Delete an exact routesudo ip route del 198.51.100.0/24 via 192.0.2.1 dev eth0 \ metric 100View examples
Show policy rulesip -details rule showView examples
Add a source policysudo ip rule add priority 1000 from 192.0.2.0/24 table \ 100View examples
Add a policy-table defaultsudo ip route replace default via 192.0.2.1 dev eth0 \ table 100View examples
Monitor network changesip monitor link address route ruleView examples
Show neighbor stateip -details neighbor show dev eth0View examples
Flush failed neighborssudo ip neighbor flush dev eth0 nud failedView examples
Show queue disciplinestc -s qdisc show dev eth0View examples
Install fq_codel root qdiscsudo tc qdisc replace dev eth0 root fq_codelView examples
Add lab delay and losssudo tc qdisc replace dev veth-test root netem delay \ 50ms loss 0.1%View examples
Remove a root qdiscsudo tc qdisc del dev veth-test rootView examples
Show iproute2 versionip -VersionView examples

Use iproute2 to inspect the kernel's live networking state and to test deliberate changes. Route, rule, link, and qdisc modifications take effect immediately, can terminate the very SSH session used to make them, and usually disappear at reboot unless expressed through the distribution's network manager. Capture current state, arrange console or out-of-band access, stage an automatic rollback, and confirm both forward and return paths before a production change.

Step by step

Detailed examples

01

Capture machine-readable state before changing the network

Record links, addresses, routes in every table, policy rules, neighbors, and qdiscs. JSON output is safer for automation than parsing aligned text, but fields vary with iproute2 and kernel versions. Include the distribution network manager's configuration because ip only shows live kernel state. Redact public topology or tunnel metadata before sharing evidence.

Create a read-only network snapshot
ip -json link show
ip -json address show
ip -json route show table all
ip -json rule show
ip -json neighbor show
tc -json -s qdisc show
Back to quick reference ↑
02

Ask the kernel which path a flow would use

ip route get performs a lookup rather than listing routes or sending traffic. Supply source, mark, input interface, protocol, or ports when policy depends on them. The result is local to the current network namespace and reflects rules plus routing tables. It does not prove the gateway, return route, firewall, NAT, DNS, or remote service is working.

Compare default and marked lookups
ip route get 203.0.113.10
ip route get 203.0.113.10 from 192.0.2.20
ip route get 203.0.113.10 from 192.0.2.20 mark 0x1
ip -6 route get 2001:db8:2::10 from 2001:db8:1::20
Back to quick reference ↑
03

Prefer exact, reversible route changes

replace is useful for converging a route, but a typographical error still changes the live forwarding plane. Specify prefix, gateway, interface, metric, table, and protocol deliberately. A gateway usually must be reachable on-link unless onlink is explicitly justified. Before a remote change, schedule an automatic rollback through an independent mechanism and retain console access; cancel it only after end-to-end verification.

Document a reversible route change
ip route show table main
ip route get 198.51.100.10 from 192.0.2.20
# Stage a tested out-of-band rollback before applying the next command.
sudo ip route replace 198.51.100.0/24 via 192.0.2.1 dev eth0 metric 100
ip route get 198.51.100.10 from 192.0.2.20
Back to quick reference ↑
04

Use explicit rule priorities and complete routing tables

The routing policy database evaluates lower numeric priorities first. Always assign a unique explicit priority and inspect existing distribution, VPN, VRF, and container rules. A custom table normally needs routes for connected networks as well as a default; otherwise gateway resolution or return paths can fail. Test representative sources and marks, then persist both rules and routes using the active network manager.

Review a source-based design before applying it
ip -details rule show
ip route show table 100
ip route get 203.0.113.10 from 192.0.2.20
# Planned state:
# ip rule add priority 1000 from 192.0.2.0/24 table 100
# ip route replace 192.0.2.0/24 dev eth0 scope link table 100
# ip route replace default via 192.0.2.1 dev eth0 table 100
Back to quick reference ↑
05

Correlate kernel events with the configuration owner

ip monitor streams changes but does not identify which process initiated them. Pair timestamps with NetworkManager, systemd-networkd, netlink-aware agents, VPN clients, container runtimes, and orchestration logs. Manual ip changes may be overwritten immediately by those managers or disappear on restart. Fix the declarative owner after proving the desired kernel state.

Observe live state and likely owners
ip -timestamp monitor link address route rule
systemctl status NetworkManager.service systemd-networkd.service --no-pager
journalctl --since today -u NetworkManager.service -u systemd-networkd.service --no-pager
Back to quick reference ↑
06

Interpret neighbor states before flushing entries

Neighbor entries represent ARP or IPv6 Neighbor Discovery and transition through states such as REACHABLE, STALE, DELAY, PROBE, FAILED, and permanent. A FAILED entry is often a symptom of VLAN, switch, address, gateway, or firewall trouble. Flush only a narrow interface and state after investigation; broad flushes cause bursts of resolution traffic and can briefly disrupt many flows.

Diagnose one interface safely
ip -statistics -details neighbor show dev eth0
ip route get 192.0.2.1
ip -statistics link show dev eth0
# If the underlying issue is fixed, remove only failed cache entries:
# sudo ip neighbor flush dev eth0 nud failed
Back to quick reference ↑
07

Apply qdiscs only with interface-specific capacity and rollback

Traffic control acts on egress, while ingress shaping normally needs redirection to an IFB or other design. Replacing the root qdisc can disrupt latency and throughput, remove child classes, and conflict with a network manager. Offloads can distort measurements. Use netem only in isolated labs, record the existing tree, confirm kernel modules, bound experiments, and test deletion or restoration before applying impairment.

Review qdisc state and a lab-only plan
tc -s -details qdisc show dev veth-test
ethtool -k veth-test
# Lab-only impairment plan:
# sudo tc qdisc replace dev veth-test root netem delay 50ms loss 0.1%
# sudo tc qdisc del dev veth-test root
Back to quick reference ↑
08

Persist through the active network manager, not ad hoc boot scripts

ip and tc modify only the current namespace's live state. Persist settings with NetworkManager, systemd-networkd, netplan, ifupdown, or distribution tooling already owning the interface; supported route-rule and qdisc features vary by version. Avoid configuring the same link in two managers. Validate a reboot or manager restart in a maintenance window with local access and an exported baseline.

Identify the live owner and versions
ip -Version
tc -Version
networkctl status --all
nmcli -t -f DEVICE,TYPE,STATE,CONNECTION device status
systemctl is-enabled NetworkManager.service systemd-networkd.service
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. iproute2 Projectip(8) Manual Pageman7.org
  2. iproute2 Projectip-route(8) Manual Pageman7.org
  3. iproute2 Projectip-rule(8) Manual Pageman7.org
  4. iproute2 Projectip-neighbour(8) Manual Pageman7.org
  5. iproute2 Projecttc(8) Manual Pageman7.org
  6. iproute2 Projecttc-netem(8) Manual Pageman7.org
  7. Linux man-pages projectNetwork Namespace Manual Pageman7.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback