tc netem fakes delay, jitter, packet loss or a slow link on one interface, so your app breaks in the lab instead of in production. You'll finish with a reversible way to apply the condition, inspect the active queueing discipline, and remove the test. The examples use NetEm through tc, from the iproute2 package version 6.1.0-1ubuntu6.4 installed here.
Allow about fifteen minutes. You need iproute2, a shell with tc, and an interface you can safely disrupt. Use a disposable test interface or a host console.
Warning: Do not apply the examples to the interface carrying your only SSH connection. NetEm affects outgoing packets, and can delay or drop the very session you're using to undo it.
First confirm the binary and package version. These are ordinary, read-only commands:
$ command -v tc
/usr/sbin/tc
$ tc -V
tc utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
Set IFACE to the interface used by your test traffic. Replace TEST_IFACE with a real name before running the assignment:
IFACE='TEST_IFACE'
ip link show dev "$IFACE"
tc qdisc show dev "$IFACE"
The last command records the current root qdisc. A normal, untouched interface often reports noqueue or a default queue, but your output is host-specific: keep it in your terminal so you know what was there before the experiment.
Checkpoint: Stop here if ip link show reports the interface doesn't exist, or if it's carrying important traffic. Fix the interface choice before using elevated privileges.
The following command changes kernel networking state, so it needs elevated privileges and may disrupt traffic on $IFACE. It installs a root NetEm qdisc with 100 ms of delay, 20 ms of jitter and 1 percent random loss:
sudo tc qdisc replace dev "$IFACE" root netem delay 100ms 20ms loss 1%
replace works whether or not the interface already has a root qdisc, but it does replace that qdisc. Do not use this on a production interface unless replacing its current traffic policy is intentional. NetEm's delay and jitter are in milliseconds, and the default delay distribution is normal unless you select another one.
Verify the setting immediately:
tc qdisc show dev "$IFACE"
qdisc netem 8001: root refcnt 2 limit 1000 delay 100ms 20ms loss 1%
The handle, reference count and formatting can differ. Look for a root netem qdisc and the values you requested, rather than expecting the sample output verbatim.
Generate traffic through the affected interface. A route or test service beats an arbitrary internet host, because the remote path adds its own delay and loss. For a simple reachability check, use a known test address:
ping -c 5 TEST_DESTINATION
Each reply should carry the extra local delay as traffic leaves through $IFACE. Packet loss is probabilistic, so five packets can't prove a 1 percent setting will visibly drop one. For a repeatable application test, run the app on the test path and collect enough requests to make its timeout and retry behaviour observable.
NetEm works on outgoing packets from the selected interface. It does not automatically apply the same condition to incoming packets, and it can't make a non-real-time Linux kernel deliver packets at perfectly exact times. Kernel timer granularity, adapter buffers and bursts can all make measured results differ from the nominal setting.
To test a slow link rather than just latency, replace the qdisc with a rate. This example models a 5 kbit/s link and adds 20 bytes of per-packet overhead:
sudo tc qdisc replace dev "$IFACE" root netem rate 5kbit 20
tc qdisc show dev "$IFACE"
qdisc netem 8001: root refcnt 2 limit 1000 rate 5Kbit 20
Treat the output as confirmation of the configured rate, not a promise about application throughput. NetEm's rate mode is limited by clock granularity and adapter buffering, so packets may arrive in bursts. If you need to model a link-layer cell scheme, the optional values after the packet overhead are cell size and per-cell overhead: rate 5kbit 20 100 5 supplies all four rate parameters.
Do not stack this on top of the previous delay settings and expect them to remain. replace replaces the root qdisc with the new NetEm configuration entirely, so include every behaviour you need in one command:
sudo tc qdisc replace dev "$IFACE" root netem rate 5mbit delay 40ms 8ms loss 0.5%
When testing is complete, remove the root qdisc with elevated privileges:
sudo tc qdisc del dev "$IFACE" root
tc qdisc show dev "$IFACE"
qdisc noqueue 0: root refcnt 2
The exact post-removal qdisc depends on the interface and its network manager. What matters is that the NetEm qdisc is gone. If the interface had a custom qdisc before the test, deleting the root qdisc does not reconstruct that old configuration: restore the original policy through the configuration system that created it, or reapply the command you recorded before step 2.
Recovery: If a test leaves a service unreachable, use the host console or a second management path and run the delete command. If you're unsure which qdisc is active, inspect it first with tc qdisc show dev "$IFACE"; do not repeatedly replace policies while troubleshooting a live connection.
reorder option must be used with delay. For example, delay 10ms reorder 25% 50% gap 5 holds packets and then sometimes sends a later one first.loss 1% is the simple random form. State and Gilbert-Elliot models describe bursts with transition probabilities, so their parameters are probabilities, not a single percentage target.ecn without one doesn't define what should be marked. With a loss model, it asks NetEm to mark packets instead of dropping them where supported.tc versions.tc qdisc show displayed the requested NetEm settings.tc qdisc show no longer reports it.