LINUXOR.SK ... open source notes ...

Namespaces 05 - NET namespace

category: learnz/namespaces · date: 2016-11-01 · updated: 2017-01-16 · theme: github

Linux Namespaces Learning · Previous: PID namespace · Next: Connecting a network namespace to the host system - with a veth pair

The Slovak original of this document: Namespaces 05 - NET namespace (slovensky).

NET (network stack) namespaces in Linux

1 Introduction

The NET namespace (network stack) isolates the network resources. Each network namespace has its own devices, addresses, routing tables, port numbers and its own "/proc/net" directory.

NET namespace
NET namespace

2 Working with NET namespaces

2.1 Creating new NET namespaces

Create two network (NET) namespaces, the first named "ns1" and the second "ns2".

asciiart
# ip netns add ns1
# ip netns add ns2

2.2 Checking that the new network (NET) namespaces exist

asciiart
# ls -l /var/run/netns
----------------------------------------------------------------------------------------------------------------
-r--r--r--. 1 root root 0 Nov 10 12:28 ns1
-r--r--r--. 1 root root 0 Nov 10 12:28 ns2

2.3 Listing every network (NET) namespace

List every network (NET) namespace with "ip".

asciiart
# ip netns list
----------------------------------------------------------------------------------------------------------------
ns2
ns1
----------------------------------------------------------------------------------------------------------------
# ip netns list-id
----------------------------------------------------------------------------------------------------------------
nsid 0 (iproute2 netns name: ns1)
nsid 1 (iproute2 netns name: ns2)

2.4 Monitoring the creation/removal of network (NET) namespaces

"ip" with the parameters "netns monitor" can monitor the creation and removal of network namespaces.

asciiart
# ip netns monitor
----------------------------------------------------------------------------------------------------------------
delete ns2
add ns2

2.5 Running processes inside network (NET) namespaces

The example below runs a BASH process in the namespace named "ns1".

asciiart
[1]TERM1# ip netns exec ns1 bash
[2]TERM1# echo $$
----------------------------------------------------------------------------------------------------------------
27768
----------------------------------------------------------------------------------------------------------------
[3]TERM1# ifconfig -a
----------------------------------------------------------------------------------------------------------------
lo: flags=8<LOOPBACK>  mtu 65536
        loop  txqueuelen 1  (Local Loopback)
        RX packets 0  bytes 0 (0.0 B)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 0  bytes 0 (0.0 B)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

Basically we "move" into namespace "ns1" and all the following commands are executed in this namespace.

In the second terminal (TERM2), check that the new network namespace exists with "namespaces-info.sh", printing only the non-default namespaces (the -n switch). Two namespaces (MNT and NET) have been created for our BASH process (27768).

asciiart
TERM2# ./namespaces-info.sh -n
----------------------------------------------------------------------------------------------------------------
---------- + ---------- + -------------------- + ----------------------------------------
PID        | PPID       | NAMESPACE            | COMMAND
---------- + ---------- + -------------------- + ----------------------------------------
18         | 2          | mnt:[4026531856]     | [kdevtmpfs]
---------- + ---------- + -------------------- + ----------------------------------------
585        | 1          | mnt:[4026532423]     | /usr/lib/systemd/systemd-udevd
---------- + ---------- + -------------------- + ----------------------------------------
720        | 1          | mnt:[4026532450]     | /usr/bin/vmtoolsd
---------- + ---------- + -------------------- + ----------------------------------------
755        | 1          | mnt:[4026532451]     | /usr/sbin/NetworkManager
---------- + ---------- + -------------------- + ----------------------------------------
854        | 755        | mnt:[4026532451]     | /sbin/dhclient
---------- + ---------- + -------------------- + ----------------------------------------
27768      | 21524      | mnt:[4026532584]     | bash
27768      | 21524      | net:[4026532455]     | bash
---------- + ---------- + -------------------- + ----------------------------------------

The previous example listed every non-default namespace, each with its i-node number. The network namespace "net:[4026532455]" has i-node number "4026532455", which is the i-node number of the file "/var/run/netns/ns1". To check, print the i-node number of the file "/var/run/netns/ns1".

asciiart
# ls -lhi /var/run/netns/
----------------------------------------------------------------------------------------------------------------
4026532455 -r--r--r--. 1 root root 0 Nov 15 13:59 ns1

2.6 Removing network (NET) namespaces

Remove the network (NET) namespace named "ns1" with "ip".

asciiart
# ip netns del ns1

When a namespace is removed, every migratable physical network adapter in it is moved to the default (system) network namespace.

2.7 Network devices (adapters) that can be migrated between network (NET) namespaces

Network adapters that can be moved between network namespaces are those whose "netns-local" feature is "off", in other words those that are not local: \-- netns-local: off -> a migratable adapter \-- netns-local: on -> a non-migratable adapter (a local one)

With "ethtool" we can check which adapters are migratable. The example below checks the adapter "ens33". The output shows that "ens33" is migratable (it is not a so-called local adapter) because "netns-local" has the value "off".

asciiart
# ethtool -k ens33 | grep netns-local
----------------------------------------------------------------------------------------------------------------
netns-local: off [fixed]

Current practice (checked 2026-10)

noteThe article above is kept as it was written in 2016. This section lists what has changed since and what to do instead today.

The checks of sections 2.3 and 2.5 today:

bash
$ # ip -n ns1 -br addr
$ # lsns -t net
$ # ip netns pids ns1

Sources:

← learnz/namespaces(EN | SK)