An IP alias is an additional IP address assigned to an existing network interface, so a single network card answers on several addresses. It is the usual way to use the additional IPs of a server, for example to run several TLS sites or services each on its own address. In this tutorial you will add additional IPv4 addresses to a Debian 12 server with ifupdown, first temporarily to test them and then persistently, and verify that traffic works on each one.

Prerequisites

To follow this guide you need:

  • A server running Debian 12 that uses ifupdown (/etc/network/interfaces), which is the default on Debian. Ubuntu 24.04 uses Netplan instead and is not covered here.
  • A non-root user with sudo privileges.
  • The additional IP addresses assigned to your server, with the netmask (prefix length) given by your provider.
  • Access to the server console (for example the VNC console in the CubePath panel) in case a network change drops your SSH session.

In this guide the primary interface is ens18, the main IP is 198.51.100.10/24 and the additional IPs are 203.0.113.20 and 203.0.113.21. Replace them with your own values.

Step 1 - Identifying the network interface

List the IPv4 addresses and the default route to find the interface that carries your main IP:

ip -4 addr show
ip route show default
2: ens18: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    inet 198.51.100.10/24 brd 198.51.100.255 scope global ens18
default via 198.51.100.1 dev ens18 onlink

The interface name here is ens18. Current Debian releases use predictable names such as ens18 or enp1s0 rather than eth0, so always use the name shown on your server.

Check where that interface is configured. On most servers it is in /etc/network/interfaces; on cloud images it may be in a file under /etc/network/interfaces.d/:

grep -rn "ens18" /etc/network/interfaces /etc/network/interfaces.d/

Step 2 - Testing the additional IP temporarily

Before touching any configuration file, add the IP at runtime with ip. This change disappears on reboot, which makes it a safe test. The label option gives it the classic ens18:0 alias name:

sudo ip addr add 203.0.113.20/32 dev ens18 label ens18:0

Which prefix length to use depends on how the IP is delivered:

  • If the additional IP belongs to the same subnet as your main IP, use that subnet's prefix (for example /24).
  • If it comes from a different subnet and is routed to your server, use /32.

Check that the address is present:

ip -4 addr show dev ens18
2: ens18: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    inet 198.51.100.10/24 brd 198.51.100.255 scope global ens18
       valid_lft forever preferred_lft forever
    inet 203.0.113.20/32 scope global ens18:0
       valid_lft forever preferred_lft forever

From another machine, for example your workstation, ping the new address:

ping -c 4 203.0.113.20

If it replies, the IP works and you can make it persistent. Remove the temporary address first so it does not clash with the permanent configuration:

sudo ip addr del 203.0.113.20/32 dev ens18

Step 3 - Making the alias persistent

Back up the current configuration:

sudo cp /etc/network/interfaces /etc/network/interfaces.bak

Debian's default /etc/network/interfaces includes the line source /etc/network/interfaces.d/*, so you can keep your aliases in a separate file and leave the main configuration untouched. Confirm that the line is present:

grep source /etc/network/interfaces
source /etc/network/interfaces.d/*

Create a file for the aliases:

sudo nano /etc/network/interfaces.d/ip-aliases

Add one stanza per additional IP, numbering the aliases ens18:0, ens18:1 and so on:

auto ens18:0
iface ens18:0 inet static
    address 203.0.113.20/32

auto ens18:1
iface ens18:1 inet static
    address 203.0.113.21/32

An alias only needs its address. Do not add gateway or dns-nameservers lines: the gateway and DNS stay on the primary interface, and a second default gateway breaks routing.

If the source line is missing from your /etc/network/interfaces, add the same stanzas at the end of that file instead.

Step 4 - Bringing the aliases up

You do not need to restart all networking, which could cut your SSH session. Bring up only the new aliases:

sudo ifup ens18:0
sudo ifup ens18:1

Check that both addresses are assigned:

ip -4 addr show dev ens18
2: ens18: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    inet 198.51.100.10/24 brd 198.51.100.255 scope global ens18
       valid_lft forever preferred_lft forever
    inet 203.0.113.20/32 scope global ens18:0
       valid_lft forever preferred_lft forever
    inet 203.0.113.21/32 scope global ens18:1
       valid_lft forever preferred_lft forever

To make sure the configuration survives a reboot, reboot during a maintenance window and run the same command again:

sudo reboot

Step 5 - Verifying traffic on each IP

From your workstation, check that each additional IP answers:

ping -c 4 203.0.113.21

On the server, you can also force an outgoing request from a specific address with curl --interface. The response is the public IP the remote side sees:

curl -4 --interface 203.0.113.20 https://ifconfig.me
203.0.113.20

By default, outgoing connections still use the main IP. To serve something on an additional IP, bind the service to it, for example listen 203.0.113.20:443 ssl; in an Nginx server block.

Removing an alias

Take the alias down, then delete its stanza from /etc/network/interfaces.d/ip-aliases so it is not added again on the next boot:

sudo ifdown ens18:1
sudo nano /etc/network/interfaces.d/ip-aliases

Confirm it is gone with ip -4 addr show dev ens18.

Troubleshooting

ifup reports "unknown interface ens18:0". The file with the stanza is not being read. Check that /etc/network/interfaces contains source /etc/network/interfaces.d/*, or put the stanza in /etc/network/interfaces directly.

RTNETLINK answers: File exists. The address is already assigned, usually from the temporary test in Step 2. Remove it with sudo ip addr del 203.0.113.20/32 dev ens18 and run ifup again.

The alias is up but does not answer from outside. Check that the IP is really assigned to this server in the panel and that the prefix is correct. Also review your firewall: UFW rules that name a specific destination address must include the new IPs.

The server lost connectivity after the change. Use the console, restore the backup with sudo cp /etc/network/interfaces.bak /etc/network/interfaces, remove the alias file and reboot.

Conclusion

Your Debian 12 server now answers on several IP addresses on the same interface, and the aliases are loaded automatically at boot from their own file. As next steps, bind each service to the address it should use, configure reverse DNS for the new IPs in the CubePath panel if they send mail, and review your firewall rules so they cover every address.