Home / Alt manpages / ip-link(8)

  • ip-link(8)
  • Admin command
  • linux

Inspect and Safely Change Linux Network Links with ip link

You will finish with a small workflow for inspecting Linux network interfaces, creating and removing a disposable virtual Ethernet link, and changing an interface MTU with a clear rollback. The examples match iproute2 6.1.0, installed here as package version 6.1.0-1ubuntu6.4. Allow about fifteen minutes. You need a shell; the state-changing examples also need elevated privileges and the CAP_NET_ADMIN capability.

Checkpoint

The first half of this guide is read-only. Stop after any command if you are working on a production host and do not have a maintenance window.

Start with the installed program and package. These commands only read local state:

$ ip -V
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4

List every link:

$ ip link show

Read the output as link-layer state, not IP addressing. The first field is the interface index. The name follows it, flags appear between angle brackets, and fields such as mtu, state, master and link-netnsid describe the device and its relationships. Names such as lo, enp0s31f6, docker0 and veth... are host-specific. Do not copy a name from an example into a change command without checking it on your host.

To inspect one known device, give its name directly:

$ ip link show dev INTERFACE_NAME

Replace INTERFACE_NAME with a real name such as enp0s31f6. The dev word is optional for several subcommands, but keeping it makes the target easier to spot in a script. You can also narrow the read-only view by type or relationship:

$ ip link show type bridge
$ ip link show type vlan
$ ip link show master BRIDGE_NAME

The manpage is broad because ip link handles physical devices and many virtual types. Ask the installed binary for its command grammar, then ask about a particular type:

$ ip link help
$ ip link help vlan

The main operations are show, add, set and delete. A useful distinction is that add creates a virtual device, while set changes an existing device. Neither command assigns an IP address; use ip-address(8) for that separate layer.

Checkpoint

Before using set or delete, run ip link show dev INTERFACE_NAME again and confirm the exact target. A typo can produce a misleading "Cannot find device" error, while a correct but unintended name can disrupt traffic.

3. Create a disposable veth pair

A veth pair is two connected virtual Ethernet interfaces. It is useful for a local test and does not touch a physical cable. Creation still changes kernel networking state, so use sudo and choose names that are unlikely to collide:

$ sudo ip link add veth-demo-a type veth peer name veth-demo-b
$ ip link show dev veth-demo-a
$ ip link show dev veth-demo-b

Both devices should appear. They are normally down until you explicitly bring them up. This example does not place either end in another network namespace and does not add addresses, routes or firewall rules.

When the test is over, remove one end. Removing a veth end removes its peer too:

$ sudo ip link delete dev veth-demo-a
$ ip link show dev veth-demo-a
Device "veth-demo-a" does not exist.

The second lookup is expected to fail because the pair has been removed. If you need to keep the interfaces for another test, omit the delete command and record their names. Do not delete a similarly named device without checking it first.

4. Change an MTU and put it back

Changing an MTU can interrupt traffic and can affect packets flowing through a bridge or tunnel. Record the current value before changing it. The following example targets a placeholder interface, so it is safe to copy only after replacing the name:

$ ip link show dev INTERFACE_NAME
$ sudo ip link set dev INTERFACE_NAME mtu 1400
$ ip link show dev INTERFACE_NAME

Use a value supported by the device and the path beyond it. A successful command usually prints nothing; the second show is the verification. If the old value was 1500, restore it with:

$ sudo ip link set dev INTERFACE_NAME mtu 1500
$ ip link show dev INTERFACE_NAME

Use the value you actually recorded, not automatically 1500. A device carrying VLAN or tunnel traffic may need a different value, and changing it while a service is busy can cause packet loss. If the link is managed by NetworkManager, systemd-networkd or another service, its configuration may later overwrite a manual change. Make the persistent change in that manager's configuration instead of treating ip link set as permanent.

5. Create a VLAN only when the parent is confirmed

The manpage's representative VLAN form is:

$ sudo ip link add link PARENT_DEVICE name VLAN_DEVICE type vlan id VLAN_ID

Replace PARENT_DEVICE with the real lower device, VLAN_DEVICE with a new name such as enp0s31f6.10, and VLAN_ID with the required numeric identifier. Verify the parent first:

$ ip link show dev PARENT_DEVICE
$ sudo ip link add link PARENT_DEVICE name VLAN_DEVICE type vlan id VLAN_ID
$ ip link show dev VLAN_DEVICE

This creates the link but does not bring it up or assign an address. If it was created by mistake, remove exactly that virtual device:

$ sudo ip link delete dev VLAN_DEVICE
$ ip link show dev VLAN_DEVICE
Device "VLAN_DEVICE" does not exist.

Do not invent a VLAN ID or parent from a network diagram. The VLAN tag, switch port configuration and host network manager must agree. A syntactically valid command can still disconnect a host from its network.

For the disposable veth pair, you can change operational state without involving a physical link:

$ sudo ip link add veth-demo-a type veth peer name veth-demo-b
$ sudo ip link set dev veth-demo-a up
$ sudo ip link set dev veth-demo-b up
$ ip link show dev veth-demo-a
$ ip link show dev veth-demo-b

The flags should include UP. Take the pair down before deleting it if you want the sequence to be explicit:

$ sudo ip link set dev veth-demo-a down
$ sudo ip link set dev veth-demo-b down
$ sudo ip link delete dev veth-demo-a

If a command returns "Operation not permitted", check both privilege and capability. If it returns "Cannot find device", inspect ip link show for the exact name, including spelling and case. If a create command says the name already exists, inspect that device before deciding whether it is a leftover test link or an in-use interface. For a network namespace move, remember that loopback, bridges and wireless devices have restrictions; the manpage documents those limits and points to ethtool for the netns-local flag.

Done means

  • You can identify the installed iproute2 version and the exact interface name.
  • You can use ip link show and type filters without changing state.
  • You can create and remove a named veth test pair with elevated privileges.
  • You record an MTU before changing it and know the command that restores it.
  • You verify a VLAN parent and understand that link creation does not configure IP addresses.