skip to content

You log into a modern minimal Linux host and find that `netstat`, `ifconfig` and `arp` are not installed. Which iproute2 commands replace each of them, and why did distributions move away from the net-tools versions?

level: juniorimportance: nice to knowfreq 45%

answer

  1. net-tools versus iproute2
  2. four ip objects plus ss
  3. netlink instead of parsing /proc
  4. the old tools cannot see namespaces

basics

~20 s

Use iproute2: ss replaces netstat, ip addr and ip link replace ifconfig, ip route replaces route, ip neigh replaces arp, and ip -s link replaces netstat -i. Distributions dropped net-tools because it was unmaintained and never covered modern kernel features.

solid answer

~40 s

They come from the deprecated **net-tools** package, and iproute2 replaces all of them. `netstat -tulpn` becomes `ss -tulpn`; `ifconfig` becomes `ip addr show` for addresses and `ip link show` for the link layer; `ifconfig eth0 up` becomes `ip link set eth0 up`; `route -n` becomes `ip route show`; `arp -n` becomes `ip neigh show`; `netstat -i` becomes `ip -s link`; `netstat -s` is best served by `nstat`. The move happened because net-tools was effectively unmaintained and its `/proc`-parsing approach scaled badly, while iproute2 talks netlink and exposes things the old tools simply cannot express — multiple addresses per interface, policy routing tables, VRFs, tunnels, network namespaces. `ip -br addr` gives a compact one-line-per-interface view when you want `ifconfig`-style brevity.

go deeper

for a junior

Be able to give the four core substitutions without hesitating — ss for netstat, ip addr/ip link for ifconfig, ip route for route, ip neigh for arp — and know why "command not found" is expected on a minimal host.

for a middle

Explain the underlying reason: netlink versus parsing /proc, and features net-tools cannot express such as several addresses on one interface or multiple routing tables. Know ip -s link as the netstat -i replacement.

for a senior

Judge when the old tool would actively mislead — namespaced containers, multi-homed hosts, policy routing — and modernise runbooks rather than reinstalling net-tools onto production images.

for a principal

Treat it as estate hygiene: which diagnostic tooling is guaranteed present in your base images, how operators are trained on it, and how you retire commands from documentation so nobody debugs a live incident against output that cannot show the truth.

## Why the old commands are gone `ifconfig`, `route`, `arp` and `netstat` ship in **net-tools**, a package that predates most of the Linux networking stack people use today. It was barely maintained for years, and its design — reading and parsing text files under `/proc/net` — both scales poorly and cannot represent features the kernel gained later. **iproute2** replaced it: a single `ip` command plus `ss`, talking to the kernel over netlink, which is a structured binary interface built for exactly this. Most distributions now install iproute2 by default and net-tools not at all, especially on minimal images and container base images. Reaching for `ifconfig` on a modern host and finding "command not found" is a routine experience, and installing net-tools to get it back is the wrong reflex. ## The mapping | net-tools | iproute2 | |---|---| | `ifconfig` | `ip addr show` (addresses), `ip link show` (link state) | | `ifconfig eth0 up` / `down` | `ip link set eth0 up` / `down` | | `ifconfig eth0 10.0.0.5/24` | `ip addr add 10.0.0.5/24 dev eth0` | | `route -n` | `ip route show` | | `route add default gw 10.0.0.1` | `ip route add default via 10.0.0.1` | | `arp -n` / `arp -a` | `ip neigh show` | | `netstat -tulpn` | `ss -tulpn` | | `netstat -tanp` | `ss -tanp` | | `netstat -r` | `ip route show` | | `netstat -i` | `ip -s link` | | `netstat -s` | `nstat` | Two conveniences make the transition easier. `ip` accepts unambiguous abbreviations, so `ip a`, `ip l`, `ip r` and `ip n` all work interactively. And `-br` (brief) gives the compact table people miss from `ifconfig`: ```bash ip -br addr # lo UNKNOWN 127.0.0.1/8 ::1/128 # enp3s0 UP 10.0.1.7/24 fe80::a00:27ff:fe4e:66a1/64 ``` `ip -c addr` adds colour, which is genuinely useful when scanning state at 3am. ## What the new tools show that the old ones could not This is the part that makes the change more than cosmetic, and it is what an interviewer is listening for: - **Multiple addresses per interface.** `ip addr` lists every address on an interface as a first-class entry. net-tools expressed extra addresses through alias interfaces like `eth0:0`, a fiction that does not correspond to anything in the modern kernel. - **Multiple routing tables and policy routing.** `ip rule` and `ip route show table <name>` describe source-based and policy routing; `route` only ever knew about one table. - **Modern link types.** Bridges, bonds, VLANs, tunnels, veth pairs, VRFs — created and inspected through `ip link`, invisible or unmanageable through `ifconfig`. - **Network namespaces.** `ip netns` and `ip -n <ns>` operate per namespace, which is the foundation of container networking. net-tools has no concept of them. - **Scale.** On a host with tens of thousands of sockets, `ss` returns promptly where `netstat` grinds, because it asks the kernel for exactly the families and states it wants instead of parsing everything. There is also a subtle accuracy point: because net-tools reads `/proc` text that is regenerated as it is read, its output on a busy host can be internally inconsistent, whereas the netlink dump is a coherent snapshot. ## Interface counters, specifically `netstat -i` printed a per-interface packet and error table; the equivalent is `ip -s link`: ```bash ip -s link show dev enp3s0 # RX: bytes packets errors dropped ... # 1394822 9021 0 0 # TX: bytes packets errors dropped ... # 2210431 11002 0 0 ``` That is the fast way to see whether an interface is registering errors or drops at all, before you go deeper with driver-level statistics. ## The practical habit Learn the four `ip` objects — `addr`, `link`, `route`, `neigh` — plus `ss`, and you have covered essentially everything net-tools did. When you are handed a runbook full of `ifconfig`, translate it rather than installing net-tools onto the host; the old command's output will be misleading on exactly the modern setups (multiple addresses, namespaces, non-Ethernet link types) where you most need the truth.

  • Somebody suggests just installing net-tools so the old commands work. What would you say?
    That it papers over the gap and can mislead you. `ifconfig` cannot represent multiple addresses per interface honestly, knows nothing about policy routing tables or network namespaces, and `netstat` is slow on socket-heavy hosts. On the setups where you most need accurate output, the old tools are least accurate. Translating the runbook is a one-time cost; carrying a misleading tool is permanent.
  • Which `ip` command shows per-interface packet, error and drop counters?
    `ip -s link` — the `-s` (statistics) flag adds RX and TX byte, packet, error and drop counters to each interface, which is the replacement for `netstat -i`. Repeating `-s` twice gives a more detailed breakdown. It is the first place to look for interface-level loss before dropping into driver-specific statistics.

saying these in an interview costs you the question

  • Insisting ifconfig is still the normal tool
  • Thinking ip addr and ip link are interchangeable
  • Believing eth0:0 aliases are how extra addresses work
  • Assuming net-tools output is namespace-aware

context