Knowledge

IP Aliasing: How to Assign Multiple IP Addresses to One Interface

IP aliasing is the practice of assigning more than one IP address to a single network interface. It lets one physical or virtual network adapter receive traffic for multiple addresses—without adding another network card. Although the phrase IP aliasing is still widely used, modern Linux systems generally treat this as adding multiple addresses to one interface, not creating separate eth0:1-style virtual interfaces.

What is IP aliasing?

IP aliasing assigns two or more IPv4 or IPv6 addresses to the same network interface. For example, a server with one interface called ens3 could use:

192.0.2.10/24
192.0.2.11/24
2001:db8:100::10/64

All three addresses are associated with the same interface and MAC address. Applications can listen on a specific address or on all available addresses, depending on their configuration.

Older Linux configurations often represented an additional IPv4 address with a label such as eth0:0 or eth0:1. These labels are legacy conventions, not separate physical interfaces. Current networking tools use the ip address command and allow several addresses to be attached directly to one device.

Why use multiple IP addresses on one interface?

IP aliasing is useful when a host needs distinct network identities but does not need another physical network connection.

Common use cases include:

  • Hosting several SSL/TLS sites, services, or tenants on separate IP addresses.
  • Migrating an application or server address with minimal downtime.
  • Binding a service to a dedicated management, API, or public-facing address.
  • Running mail, DNS, proxy, or legacy applications that require separate source or destination IPs.
  • Supporting a staged network migration while old and new addresses remain active.
  • Testing multi-address application behavior in a lab or virtual machine.

For many websites, name-based virtual hosting is enough. Use an additional IP only when a technical, operational, security, or compatibility requirement calls for one.

How IP aliasing works

Every network interface can have multiple IP addresses. When a packet arrives for one of those local addresses, the operating system accepts it through the same interface. Outbound traffic can use a particular source address if an application binds to it or if routing rules select it. IP aliasing does not create extra bandwidth or isolate traffic like a separate VLAN, interface, or network namespace would. The addresses still share the same adapter, link, and most network-level behavior.

When addresses belong to different subnets, routing becomes more important. Define the correct routes and, where necessary, source-based routing so replies leave through the expected gateway and address.

ip aliasing

Benefits of IP aliasing

  • Lower infrastructure overhead: One adapter can serve multiple addresses, reducing the need for extra hardware or virtual NICs.
  • Flexible service separation: Services can bind to different addresses while sharing the same host.
  • Simpler address transitions: Keep an old address online while clients, DNS records, and firewall rules move to a new one.
  • Legacy compatibility: Some applications, access-control lists, and external systems expect a dedicated source IP.
  • IPv4 conservation: It avoids needless interfaces, although it does not reduce the number of public IP addresses required.

Limitations and risks to consider

  • No network isolation: Multiple addresses on one interface do not replace VLANs, firewalls, or separate network namespaces.
  • Routing complexity: Addresses in different networks may need explicit routes, route metrics, or policy routing.
  • Source-address surprises: A service or outbound connection may use an unexpected source address unless you bind it or configure routing deliberately.
  • Provider restrictions: Cloud platforms and hosting providers may require you to assign secondary private or public IPs in their control plane before the server can use them.
  • Persistence matters: A command-line change usually disappears after a restart unless you add it to the operating system’s network configuration.
  • Address conflicts: Never assign an address already in use.

How to add a temporary IP address on Linux

Use the ip command for a quick, non-persistent change. First, identify the interface and its current addresses:

ip address show

Then add an address:

sudo ip address add 192.0.2.11/24 dev ens3

Verify the assignment:

ip address show dev ens3

To remove the address:

sudo ip address delete 192.0.2.11/24 dev ens3

This approach is ideal for testing, but the change is normally lost at reboot or when the interface is reconfigured.

How to make IP aliasing persistent on Ubuntu with Netplan

On Ubuntu Server systems that use Netplan, list all static addresses under the same interface in a YAML file under /etc/netplan/:

network:
  version: 2
  renderer: networkd
  ethernets:
    ens3:
      addresses:
        - 192.0.2.10/24
        - 192.0.2.11/24
      routes:
        - to: default
          via: 192.0.2.1
      nameservers:
        addresses:
          - 192.0.2.53
          - 198.51.100.53

Before applying a remote change, validate the YAML and use a rollback-safe workflow where available:

sudo netplan try

If the configuration looks correct, apply it:

sudo netplan apply

Then confirm both addresses are present:

ip addr show dev ens3

Netplan can also add a static address alongside an address received through DHCP. Be cautious with gateways: an interface should have an intentional default-route design, especially when addresses span multiple networks.

Best practices for configuring IP aliases

  • Record the purpose and owner of every address in IP address management documentation.
  • Use CIDR prefix lengths that match the assigned subnet.
  • Check your provider’s secondary IP and anti-spoofing requirements before configuring a cloud VM.
  • Bind sensitive services to their intended address instead of listening on every interface.
  • Update firewall rules, monitoring, reverse DNS, and allowlists for each address as needed.
  • Test connectivity from another host, not only from the server itself.
  • Make persistent configuration changes through the platform’s supported network manager.
  • Plan routes and source address selection before placing addresses from different subnets on the same interface.

Troubleshooting IP aliasing

If the address appears locally but cannot be reached, work through these checks:

  • Confirm the address is assigned: Run ip addr show dev <interface>.
  • Check the route: Run ip route and ensure the subnet and default route are correct.
  • Review firewall rules: Inspect the host firewall and any cloud security groups or network ACLs.
  • Validate the upstream network: Verify that the switch, router, or cloud provider recognizes the secondary address.
  • Look for duplicate IP use: An ARP conflict can cause intermittent or misleading results.
  • Test the bound service: Make sure the application is listening on the expected IP address and port.

Useful commands include:

ip addr
ip route
ss -lntup
ping -I 192.0.2.11 198.51.100.1

IP aliasing vs. virtual interfaces, VLANs, and load balancers

Option What it provides Best for
IP aliasing Multiple IP addresses on one interface Address-level service separation and migrations
VLAN Layer 2 segmentation Separating networks or security zones
Virtual interface / extra NIC Another logical network attachment Different networks, routes, or provider networks
Load balancer Traffic distribution and high availability Scaling and protecting application traffic

Choose IP aliasing when you only need additional addresses on the same network path. Choose VLANs, extra interfaces, policy routing, or load balancing when you need stronger separation, different traffic paths, or redundancy.

Conclusion

IP aliasing is a practical way to run multiple IP addresses through one network interface. It can simplify service separation, address migrations, and compatibility requirements without adding network hardware. For modern Linux environments, configure multiple addresses directly on the interface, make the configuration persistent through the supported network manager, and plan routing and security controls before putting it into production.

Knowledge

Address Space Layout Randomization (ASLR): How It Works and Why It Matters

Address space layout randomization (ASLR) is a security technique that makes memory-based attacks harder to...

Wormhole Switching: How It Works, Benefits, and Limits

Wormhole switching is a network flow-control technique that divides a packet into small pieces called...

Cut-Through Switching: How It Works, Benefits, and Trade-Offs

Cut-through switching is a network switching method designed to reduce latency. Instead of waiting for...