Linux网络属性配置—iproute命令家族

ip命令:
show / manipulate routing, devices, policy routing and tunnels
ip [ OPTIONS ] OBJECT { COMMAND | help }
OBJECT := { link | addr | route | netns  }
ip  OBJECT:
ip link: network device configuration
         ip  link  show  – display device attributes
  1. ]# ip link show
  2. 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
  3. link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
  4. 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  5. link/ether 00:0c:29:ae:e4:d8 brd ff:ff:ff:ff:ff:ff
  6. 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  7. link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
ip  link  set – change device attributes
dev NAME (default):指明要管理的设备,dev关键字可省略;
up和down:
multicast on或multicast off:启用或禁用多播功能;
name NAME:重命名接口
mtu NUMBER:设置MTU的大小,默认为1500;
netns PID:ns为namespace,用于将接口移动到指定的网络名称空间;
  1. ]# ip link set eth1 down
  2. ]# ip link show eth1
  3. 3: eth1: <BROADCAST,MULTICAST> mtu 1500 qdisc pfifo_fast state DOWN qlen 1000
  4. link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
  5. ]# ip link set eth1 multicast off ]# ip link show eth1 3: eth1: <BROADCAST> mtu 1500 qdisc pfifo_fast state DOWN qlen 1000 link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
  1. ]# ip link set eth1 name exxx
  2. ]# ip link show
  3. 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
  4. link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
  5. 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  6. link/ether 00:0c:29:ae:e4:d8 brd ff:ff:ff:ff:ff:ff
  7. 3: exxx: <BROADCAST> mtu 1500 qdisc pfifo_fast state DOWN qlen 1000
  8. link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
  1. ]# ip link set eth1 mtu 2000
  2. ]# ip link show eth1
  3. 3: eth1: <BROADCAST> mtu 2000 qdisc pfifo_fast state DOWN qlen 1000
  4. link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
ip  link  help –  显示简要使用帮助;
ip netns:  – manage network namespaces.
ip  netns  list:列出所有的netns
ip  netns  add  NAME:创建指定的netns
ip  netns  del  NAME:删除指定的netns
ip  netns   exec  NAME  COMMAND:在指定的netns中运行命令
  1. ]# ip netns list
  2. ]# ip netns add netspace
  3. ]# ip netns list
  4. netspace
ip address – protocol address management.
ip address add – add new protocol address
                ip address { add | del } IFADDR dev STRING
        ip address { show | flush } [ dev STRING ] [label PATTERN ]
ip  addr  add  IFADDR  dev  IFACE
[label NAME]:为额外添加的地址指明接口别名;
[broadcast ADDRESS]:广播地址;会根据IP和NETMASK自动计算得到;
[scope SCOPE_VALUE]:
global:全局可用;
link:接口可用;
host:仅本机可用;
  1. ]# ip addr add 192.168.1.10/24 dev eno16777736
  2. ]# ip addr show eno16777736
  3. 2: eno16777736: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  4. link/ether 00:0c:29:60:1e:7a brd ff:ff:ff:ff:ff:ff
  5. inet 10.0.1.20/24 brd 10.0.1.255 scope global eno16777736
  6. valid_lft forever preferred_lft forever
  7. inet 192.168.1.10/24 scope global eno16777736
  8. valid_lft forever preferred_lft forever
  1. ]# ip addr add 192.168.2.10/24 dev eno16777736 label eno16777736:0
  2. ]# ip addr show eno16777736
  3. 2: eno16777736: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  4. link/ether 00:0c:29:60:1e:7a brd ff:ff:ff:ff:ff:ff
  5. inet 10.0.1.20/24 brd 10.0.1.255 scope global eno16777736
  6. valid_lft forever preferred_lft forever
  7. inet 192.168.1.10/24 scope global eno16777736
  8. valid_lft forever preferred_lft forever
  9. inet 192.168.2.10/24 scope global eno16777736:0
  10. valid_lft forever preferred_lft forever
ip address delete – delete protocol address
ip addr  delete  IFADDR  dev  IFACE 
  1. ]# ip addr del 192.168.2.10/24 dev eno16777736
  2. ]# ip addr del 192.168.1.10/24 dev eno16777736
  3. ]# ip ad sh eno16777736
  4. 2: eno16777736: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  5. link/ether 00:0c:29:60:1e:7a brd ff:ff:ff:ff:ff:ff
  6. inet 10.0.1.20/24 brd 10.0.1.255 scope global eno16777736
  7. valid_lft forever preferred_lft forever
ip address show – look at protocol addresses
ip  addr   list  [IFACE]:显示接口的地址;
  1. ]# ip addr show eno16777736
  2. 2: eno16777736: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  3. link/ether 00:0c:29:60:1e:7a brd ff:ff:ff:ff:ff:ff
  4. inet 10.0.1.20/24 brd 10.0.1.255 scope global eno16777736
  5. valid_lft forever preferred_lft forever
  6. inet6 fe80::20c:29ff:fe60:1e7a/64 scope link
  7. valid_lft forever preferred_lft forever
ip address flush – flush protocol addresses
ip  addr  flush  dev  IFACE
  1. ]# ip addr add 10.10.10.10/8 dev eth1 label eth1:0
  2. ]# ip addr add 172.16.1.100/16 dev eth1 label eth1:1
  3. ]# ip addr show eth1
  4. 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  5. link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
  6. inet 192.168.1.100/24 brd 192.168.1.255 scope global eth1
  7. inet 10.10.10.10/8 scope global eth1:0
  8. inet 172.16.1.100/16 scope global eth1:1

  9. ]# ip addr flush dev eth1 ]# ip addr show eth1 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:ae:e4:e2 brd ff:ff:ff:ff:ff:ff
ip route – routing table management
ip route add – add new route
ip route change – change route
ip route replace – change or add new one
ip  route   add  TYPE PREFIX  via GW  [dev  IFACE]  [src SOURCE_IP]
  1. ]# ip route add 172.16.0.0/16 via 10.0.1.2 dev eth0 src 10.0.1.6
  2. ]# ip route show
  3. 10.0.1.0/24 dev eth0 proto kernel scope link src 10.0.1.6
  4. 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.10
  5. 172.16.0.0/16 via 10.0.1.2 dev eth0 src 10.0.1.6
  6. default via 10.0.1.2 dev eth0
  1. ]# ip route add default via 10.0.1.2 dev eth0
  2. ]# ip route show
  3. 10.0.1.0/24 dev eth0 proto kernel scope link src 10.0.1.6
  4. 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.10
  5. 172.16.0.0/16 via 10.0.1.2 dev eth0 src 10.0.1.6
  6. default via 10.0.1.2 dev eth0
         ip route delete – delete route
 ip  route  del  TYPE PRIFIX 
  1. ]# ip route del 172.16.0.0/16
  2. ]# ip route del default
  3. ]# ip route show
  4. 10.0.1.0/24 dev eth0 proto kernel scope link src 10.0.1.6
  5. 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.10
ip route show – list routes
TYPE PRIFIX  
ip route get – get a single route
ip  route  get  TYPE PRIFIX
  1. ]# ip route get 192.168.1.0/24
  2. broadcast 192.168.1.0 dev eth1 src 192.168.1.10
  3. cache <local,brd> mtu 1500 advmss 1460 hoplimit 64
ss命令:
ss  [options]  [ FILTER ]
选项:
-t:TCP协议的相关连接
-u:UDP相关的连接
-w:raw socket相关的连接
-l:监听状态的连接
-a:所有状态的连接
-n:数字格式
-p:相关的程序及其PID
-e:扩展格式信息
-m:内存用量
-o:计时器信息
FILTER := [ state TCP-STATE ]  [ EXPRESSION ]
TCP的常见状态:
TCP FSM:
LISTEN:监听
ESTABLISEHD:建立的连接
FIN_WAIT_1:
FIN_WAIT_2:
SYN_SENT:
SYN_RECV:
CLOSED:
EXPRESSION:
dport = 
sport = 
示例:'( dport = :22 or sport = :22)’
~]# ss   -tan    ‘(  dport = :22 or sport = :22  )’
~]# ss  -tan  state  ESTABLISHED

原创文章,作者:N24_ViCi,如若转载,请注明出处:http://www.178linux.com/62526

(0)
N24_ViCiN24_ViCi
上一篇 2016-12-04
下一篇 2016-12-04

相关推荐

  • grep、egrep正则表达式之初窥门径

    何谓正则表达式 正则表达式,又称正规表示法、常规表示法(Regular Expression,在代码中常简写为regex、regexp或RE),是一类字符所书写的模式,其中许多字符不表示其字面意义,而是表达控制或通配等功能。正则表达式使用单个字符串来描述、匹配一系列符合某个句法规则的字符串。在很多文本编辑器里,正则表达式通常被用来检索、替换那些符合某个模式的…

    2015-03-19
  • 初识Nginx

    前言:   Nginx介绍:    Nginx(engine x)是由俄罗斯人logor sysoev研发的;官方网站:nginx.org;nginx是一个轻量级的高性能的web服务器和反向代理服务器;nginx本身一个处理静态资源的web服务器,但是通过加装fastcgi等模块,可是支持动态资源;可以为IMAP/POP3/SM…

    Linux干货 2015-06-23
  • 虚拟化网络之OpenvSwitch(三)

    上一篇介绍了openvswitch利用GRE协议,搭建多台宿主机的虚拟网络,接下来在利用vxlan通道搭建一个跨多宿主机的虚拟化网络,深入了解openvswitch的功能。 一、实验拓扑 ip地址分配:  A1:192.168.10.1/24  A2:192.168.10.10/24   B1:192.168.10.2…

    系统运维 2016-03-27
  • Memcache存储大数据的问题

    Memcache存储大数据的问题   huangguisu       Memcached存储单个item最大数据是在1MB内,如果数据超过1M,存取set和get是都是返回false,而且引起性能的问题。 我们之前对排行榜的数据进行缓存,由于排行榜在我们所有sql select…

    Linux干货 2015-05-05
  • 第三周

    第三周 1.列出当前系统上所有已经登录的用户的用户名,注意:同一个用户登录多次,则只显示一次即可。 [root@node1 ~]# who -q | sed -n ‘1p’ centos root fedora redhat mint 2.取出最后登录到当前系统的用户的相关信息。 [root@node1 ~]# who -a | tail -1 mint +…

    Linux干货 2017-07-25
  • linux用户权限管理

    用户: 管理员–root= 0 普通用户–(1-65535) 系统用户–(1-499),(1-999) 登录用户–(500+),(1000+) 用户和组的配置文件位置: /etc/passwd– 存储系统用户所有信息 /etc/group– 存储用户组的所有信息 /etc/shadow&…

    2017-04-02

评论列表(1条)

  • 马哥教育
    马哥教育 2016-12-14 15:45

    博客完成的非常好,有图有真相,有实验结果。加油!