Adding an address with ip address add is quick, reversible and easy to get wrong on the wrong interface. This guide is a small, reversible workflow for inspecting an interface's IPv4 and IPv6 addresses, adding one address, checking the result, and removing that exact address. The examples match the installed iproute2 6.1.0 command on this machine.
Allow about ten minutes. You need a shell and an interface name. Reading addresses is an ordinary, unprivileged operation. Adding, changing, deleting or flushing addresses changes live networking and normally requires root, so use sudo only for those commands. The example address uses documentation space and is not a usable public address.
Confirm the utility and package version before relying on option details. This does not change the network:
$ ip -Version
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
The command is part of the iproute2 package. The short form ip addr is commonly used, but this guide spells out ip address so that the object being managed is obvious.
Start with a read-only inventory. The show subcommand is optional, so both forms display protocol addresses on all interfaces:
$ ip address show
$ ip address
Output is grouped by interface. Look for lines beginning with inet for IPv4 and inet6 for IPv6. The prefix length after the slash describes the network prefix, while scope host, scope link and scope global describe where the address is valid. Interface names and addresses are host-specific, so do not copy them into a script as if they were defaults.
Checkpoint: choose the interface you intend to inspect. Replace IFACE below with a real name from the first column of your output, such as ens18 or lo:
$ IFACE='IFACE'
$ ip address show dev "$IFACE"
If this reports that the device does not exist, correct the name first. Running the command with sudo will not make a misspelled interface appear.
Use selectors when the complete inventory is distracting. This shows only addresses attached to one device:
$ ip address show dev "$IFACE"
To show only active interfaces, use up. To match addresses in a prefix, use to; to select a scope, use scope:
$ ip address show up
$ ip address show dev "$IFACE" scope global
$ ip address show to 192.0.2.0/24
These filters affect what is displayed, not what exists. A common trap is treating scope global as a family selector: it can match both IPv4 and IPv6 addresses whose scope is global. If you need to identify a particular address family, read the inet or inet6 label in the output.
Only continue when you have identified the correct interface and understand that the address change is live. Adding an address can affect source-address selection and applications that bind to all local addresses. Do not do this on a production interface during an outage unless the change is part of an approved recovery procedure.
The following adds an IPv4 address from TEST-NET-1. It uses sudo because the kernel network configuration is being changed:
$ sudo ip address add 192.0.2.25/24 dev "$IFACE"
The normal successful output is nothing and the exit status is zero. Verify the exact address rather than assuming that a quiet command succeeded:
$ ip address show dev "$IFACE" to 192.0.2.25/32
inet 192.0.2.25/24 scope global IFACE
valid_lft forever preferred_lft forever
The interface name and formatting can differ. The useful check is that 192.0.2.25 appears on the intended device. With no lifetime specified, the installed manual documents both lifetimes as forever. That does not mean the setting survives a reboot: this command changes the running kernel state, not your distribution's persistent network configuration.
Restore the previous state by deleting the same address from the same interface. This is another live change, so keep the address and device visible while reviewing the command:
$ sudo ip address delete 192.0.2.25/24 dev "$IFACE"
$ ip address show dev "$IFACE" to 192.0.2.25/32
The final command should produce no matching address. If you used a different prefix length or added a label, repeat the identifying arguments accurately. The manual says deletion arguments correspond to addition arguments, while the device name is required.
If the address was added by a service or network manager, deleting it by hand may cause that service to add it again. In that case, find and change the owning configuration instead of repeatedly deleting the symptom. Do not edit a persistent configuration file unless you know which network stack owns the interface and have a rollback copy.
For IPv6, valid_lft controls how long the address remains valid. Once it expires, the kernel removes it. preferred_lft controls whether new outgoing connections choose it; an address can remain valid while no longer being preferred. Both accept forever or a number of seconds:
$ sudo ip address add 2001:db8:1234::25/64 dev "$IFACE" valid_lft 300 preferred_lft 120
This is a documentation address and is suitable only for syntax testing on a controlled interface. Remove it explicitly after checking it, or wait for its valid lifetime:
$ sudo ip address delete 2001:db8:1234::25/64 dev "$IFACE"
By default, adding an address can create an automatic route for its network prefix. The noprefixroute configuration flag suppresses that automatic route. Use it only when your routing design deliberately supplies the route elsewhere, and verify the routing result separately with ip route. An address change is not a substitute for checking routing.
ip address flush removes every address matching its selectors. The installed manual specifically warns that flush is unforgiving. Never use a broad command such as this on a live interface:
$ sudo ip address flush dev "$IFACE"
It can remove the address used by your current remote session, including IPv6 link-local addresses. Recovery may require console access or a network service restart, and the exact repair depends on the system's network manager. If you must remove one address, use ip address delete with its exact address and device. Before any approved flush, save the current state for reference:
$ ip address save dev "$IFACE" > "$IFACE-addresses.save"
The save file is a record for review or a later restore workflow; it is not a promise that restoring it will repair every service-managed configuration. Treat it as potentially sensitive because interface addresses reveal network details.
iproute2 version and identified the real interface name.dev, scope, to and up.