Linux Sysadmin · Lesson 1 · 25 min

Networking: ifconfig vs ip

Old tutorials say ifconfig. Windows people type ipconfig. Modern Linux uses ip. Let's sort out all three, learn how a server finds its way to the internet, and then fix one that can't.

You will learn

  • The network basics: IP address, subnet, gateway, DNS, DHCP
  • The old tools (ifconfig, route, netstat, arp) vs the new ones (ip, ss), plus the Windows equivalents
  • A step-by-step way to find out where a connection breaks
  • How DNS works on each family (they're surprisingly different)
  • The biggest difference of all: NetworkManager / nmcli on Rocky vs Netplan on Ubuntu Server

Networking in five minutes

                    INTERNET  (8.8.8.8, google.com, …)
                        │
               ┌────────┴────────┐
               │  router 192.168.1.1  ← the GATEWAY (the door out) + DHCP + DNS
               └────────┬────────┘
      ┌─────────────────┼──────────────────┐
  laptop             server               printer
  192.168.1.23       192.168.1.50         192.168.1.80
               (all in 192.168.1.0/24 — the same local network)

Old tools, new tools, Windows tools

For decades Linux used the net-tools package: ifconfig, route, netstat, arp. It stopped being developed around 2011 and was replaced by iproute2: the ip and ss commands. Today neither family installs net-tools by default, so ifconfig just says “command not found.”

I want to…Modern LinuxOld Linux (net-tools)Windows
See my IP addressesip a (or ip -br a)ifconfigipconfig
See everything, incl. DNSip a + ip r + resolvectl status / nmcli—ipconfig /all
See my gateway / routesip routeroute -nroute print
See devices on my LANip neigharp -aarp -a
See listening portsss -tlnpnetstat -tlnpnetstat -an
Trace the pathtracepath / traceroutetraceroutetracert
Look up a namedig / host / nslookupnslookupnslookup
Test a connectionping -c 4 (runs forever without -c!)pingping (stops after 4)
Rocky / RHEL
sudo dnf install net-tools     # if you really want ifconfig
rpm -qf $(which ip)            # ip comes from "iproute"
Ubuntu / Debian
sudo apt install net-tools     # if you really want ifconfig
dpkg -S $(which ip)            # ip comes from "iproute2"

Reading ip a (and ifconfig)

Same on both
ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 …                    ← loopback (this computer)
    inet 127.0.0.1/8 scope host lo
2: enp0s3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 … state UP  ← card name, and it's UP
    link/ether 08:00:27:4c:1a:7e brd ff:ff:ff:ff:ff:ff           ← MAC address
    inet 192.168.1.50/24 brd 192.168.1.255 scope global dynamic enp0s3   ← IP + subnet; "dynamic" = from DHCP

The same card in old ifconfig style says inet 192.168.1.50 netmask 255.255.255.0: same information, different format. One real advantage of ip is that a card can have several addresses, and ifconfig only shows the first one.

Why the odd name enp0s3? Modern Linux names network cards after their physical slot (ethernet, pci bus 0, slot 3), so the names don't shuffle around when you reboot. Older systems and many cloud servers use eth0. Always check yours with ip -br link.

Same on both
ip -br a         # brief: one line per card
ip route         # "default via 192.168.1.1" ← that's your gateway
ip neigh         # who's nearby on the LAN (the ARP table)

Where does it break? The troubleshooting ladder

When “the internet doesn't work,” climb this ladder from the bottom. The first step that fails is your problem:

StepCommandIf it fails, it means…
1. Is the card up?ip -br linkUnplugged cable, or the card is switched off
2. Do I have an address?ip -br aDHCP failed, or the network config is wrong
3. Can I reach the gateway?ping -c 3 192.168.1.1Local network problem (wrong subnet, bad cable, Wi-Fi)
4. Can I reach the internet by number?ping -c 3 8.8.8.8No default route (ip route), or the router/ISP is down
5. Do names work?ping -c 3 google.comDNS is broken, even though the network itself is fine

Learn to recognize the error messages:

DNS: two very different setups

Before asking DNS, Linux checks /etc/hosts, a simple list of names and addresses that you can edit. Then it asks the DNS servers. How those are set up differs a lot between the families:

Rocky / RHEL
cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 192.168.1.1

The real DNS server is listed right there. NetworkManager writes this file, so don't edit it by hand, because your changes get overwritten. dig needs installing: sudo dnf install bind-utils

Ubuntu / Debian
cat /etc/resolv.conf
resolvectl status
nameserver 127.0.0.53     ← a local helper, not the real server!
…
Current DNS Server: 192.168.1.1

Ubuntu runs systemd-resolved, a small DNS helper on 127.0.0.53. To see the real DNS servers, use resolvectl status. dig is already installed.

Same on both
dig google.com            # full DNS answer
dig +short google.com     # just the address
dig @1.1.1.1 google.com   # ask a specific DNS server
getent hosts google.com   # what programs actually see (hosts file first, then DNS)

One more difference: Ubuntu's /etc/hosts has a line 127.0.1.1 ubuntu for the machine's own name. Rocky's doesn't.

Changing the network: the big family difference

You can change things temporarily with ip. It's great for testing, but it's forgotten at reboot:

Same on both (temporary!)
sudo ip addr add 192.168.1.99/24 dev enp0s3
sudo ip route add default via 192.168.1.1
sudo ip link set enp0s3 down      # careful over SSH!

For permanent settings, each family has its own system. Here's how to give the server a static address of .60:

Rocky / RHEL: NetworkManager
nmcli                          # overview
nmcli con show                 # connection profiles
sudo nmcli con mod enp0s3 \
  ipv4.method manual \
  ipv4.addresses 192.168.1.60/24 \
  ipv4.gateway 192.168.1.1 \
  ipv4.dns 1.1.1.1
sudo nmcli con up enp0s3       # apply it

con mod saves the profile to /etc/NetworkManager/system-connections/enp0s3.nmconnection, and con up activates it. Prefer menus? Try sudo nmtui. The old /etc/sysconfig/network-scripts/ifcfg-* files from CentOS tutorials are deprecated on Rocky 9.

Ubuntu Server: Netplan
sudo nano /etc/netplan/50-cloud-init.yaml
network:
  version: 2
  ethernets:
    enp0s3:
      dhcp4: false
      addresses:
        - 192.168.1.60/24
      routes:
        - to: default
          via: 192.168.1.1
      nameservers:
        addresses: [1.1.1.1]
sudo netplan try      # apply, auto-undo in 120 s unless you press Enter
sudo netplan apply    # apply for real

YAML is picky: use spaces, never tabs, and keep the indentation exact. Netplan warns if the file isn't private (chmod 600). Netplan hands the config to systemd-networkd. Ubuntu Desktop uses NetworkManager instead, so nmcli works there. On cloud servers, cloud-init may rewrite 50-cloud-init.yaml; its comment explains how to stop that.

Changing the network over SSH

If you change the IP of the server you're SSH'd into, your connection drops, because you were talking to the old address. Then you ssh to the new one. If you made a mistake, you may not be able to get back in at all! That's why netplan try exists: if you can't press Enter within 120 seconds, it puts the old settings back. nmcli has no undo, so double-check before con up, and keep a console handy. You can test this safely in the practice terminal. 😈

The computer's name

Same on both
hostnamectl                             # name, OS, kernel
sudo hostnamectl set-hostname webserver # permanent rename

Try it 1: explore the network

Try it 2: “the server can't reach the internet” 🔌

A student set this server up by hand and made two mistakes. Climb the ladder, find both, and fix them permanently with the right tool for the family.

Quick check

1. You type ifconfig on a fresh Rocky or Ubuntu server and get “command not found.” Why?

2. ping 8.8.8.8 works but ping google.com says “Temporary failure in name resolution.” What's broken?

3. Where does Ubuntu Server keep its permanent network settings?

4. On Ubuntu, /etc/resolv.conf says nameserver 127.0.0.53. Is DNS pointing at the wrong place?

Finished the missions and the quiz? Mark it done to track your progress.