ip netconf show reads the forwarding and filtering settings the kernel keeps for every network interface. It reports these and several other network configuration values in a compact form, without changing anything. Allow about ten minutes. You need the iproute2 package and a shell; the read-only examples normally do not require sudo.
Start by confirming which ip command is installed and which package supplied it:
$ ip -V
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
Package versions vary by distribution. This guide was checked with iproute2 6.1.0-1ubuntu6.4. The installed manual describes ip-netconf as the network configuration monitoring utility and documents the ip netconf show form.
Checkpoint: If ip is missing, install iproute2 through your normal distribution process before continuing. Do not copy a package command from another distribution into a production system.
Run the command with no device name:
$ ip netconf show
inet lo forwarding on rp_filter off mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
inet all forwarding on rp_filter strict mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
inet6 lo forwarding off mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
inet6 all forwarding off mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
Your output will contain a line for each relevant device, so it may be much longer. The command usually includes an inet section for IPv4 and an inet6 section for IPv6. It can also show aggregate entries such as all and default. With no interface argument, the utility displays the complete set rather than selecting a particular device.
Each line is a space-separated set of name and value pairs. In the example, IPv4 forwarding is on for lo, while IPv6 forwarding is off. The line also reports rp_filter, mc_forwarding, proxy_neigh and ignore_routes_with_linkdown. These are status values to read, not arguments that this command can edit.
Use dev NAME when you are troubleshooting one link. First list the names that the kernel currently knows:
$ ip -br link
lo UNKNOWN 127.0.0.1/8 ::1/128
enp0s31f6 UP
docker0 DOWN
The exact interfaces and state columns are machine-specific. Choose a name from your own output, then query it:
$ ip netconf show dev lo
inet lo forwarding on rp_filter off mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
inet6 lo forwarding off mc_forwarding off proxy_neigh off ignore_routes_with_linkdown off
This is often easier to read than the full report and safer to use in a diagnostic script. It still only reads kernel configuration. It does not bring the device up or down, change a route, or alter a sysctl.
Checkpoint: The device name in the command must match an existing link exactly. Names such as eth0 are not universal; modern systems may use predictable names such as enp0s31f6, or virtual names created by containers.
The manual ties this report to files under /proc/sys/net/ipv4/conf/ and /proc/sys/net/ipv6/conf/. A device-specific entry is represented by its interface directory, while all and default are separate aggregate or template scopes. File availability can vary with the kernel and enabled features, so check before reading a particular name:
$ for name in forwarding rp_filter mc_forwarding proxy_neigh ignore_routes_with_linkdown; do
file="/proc/sys/net/ipv4/conf/lo/$name"
if [ -r "$file" ]; then
printf '%s=' "$name"
cat "$file"
else
printf '%s=unavailable\n' "$name"
fi
done
forwarding=1
rp_filter=0
mc_forwarding=0
proxy_neigh=unavailable
ignore_routes_with_linkdown=0
ip netconf presents the settings it can report in a readable form, such as on, off, strict or loose. The two views are useful together: use ip netconf for a quick report, and a matching /proc file when it exists and a script or investigation needs one exact value.
Do not assume that all means every per-interface value is identical. It is its own scope, and some settings have separate IPv4 and IPv6 entries. Compare the family and device columns before drawing a conclusion about forwarding or filtering.
If a device name is wrong, the command reports the problem and exits non-zero:
$ ip netconf show dev definitely-not-an-interface
Device "definitely-not-an-interface" does not exist.
$ printf '%s\n' "$?"
1
Use the exit status in a check rather than treating an empty-looking result as proof that a setting is disabled:
if ip netconf show dev "$device"; then
printf '%s\n' 'Network configuration was read'
else
status=$?
printf 'Could not read configuration for %s (status %s)\n' "$device" "$status" >&2
exit "$status"
fi
Set device to a value you have validated, for example device=lo. Quote the variable so an unexpected value cannot be split into extra shell words. If the interface exists but output is incomplete, check the kernel files and system logs rather than changing values at random.
These examples are intentionally read-only. Changing forwarding or reverse-path filtering is a system and security decision that belongs to the relevant network design and change process. The ip netconf show command has no undo step because it makes no state change; if you later use a separate sysctl or networking command, record the previous value first and follow that tool's rollback procedure.
iproute2 is installed and its version is known.ip netconf show.ip netconf show dev NAME.all, default, IPv4 and IPv6 entries before interpreting a value.