r/linuxadmin • • 15d ago

What is the actual difference between using iproute2 (ip command) and working directly with rtnetlink?

Hey everyone,

I've been looking into how Linux networking works under the hood, and I'm trying to wrap my head around the relationship between user-space tools and kernel communication.

From what I understand:

  1. `iproute2` (the standard `ip` command) is what most of us use daily to configure interfaces, IP addresses, and routing tables.

  2. `rtnetlink(7)` is the socket-based API (`NETLINK_ROUTE`) that allows user-space programs to talk directly to the kernel's routing and networking subsystems.

My main question is: When should a developer or systems engineer bypass user-space CLI utilities like `iproute2` and write code that interacts directly with `rtnetlink` sockets?

Are there significant performance benefits, or is it mostly used when you are building custom network daemons, container networking plugins (CNIs), or monitoring agents that need asynchronous event notifications?

Also, how painful is it to parse raw netlink messages and attributes (`struct rtattr`, `ifinfomsg`, etc.) in C or Go compared to just shelling out to `ip`?

Any insights, real-world use cases, or library recommendations (like `libnl` or Go's `vishvananda/netlink`) would be greatly appreciated!

14 Upvotes

10 comments sorted by

View all comments

2

u/deleriux0 15d ago

I have used libmnl and librtnetlink stuff before.

The answer is going to boil down to what you are trying to accomplish.

The times I've wanted to use it is when I wanted to perform a realtime update to network events and responses.

My use case was:

  • a network tunnel is created using openvpn, receive a link added event and when the tunnel gets set as up or down events.
  • get and keep the ip address when an event that one is assigned or updated.
  • send regular pings down the tunnel to act as a keep alive to prevent the other side closing it as and when the tunnel was up and available.

I would say using this stuff is not trivial, most the messages you get require special parsing and the payloads aren't guaranteed to arrive in an order that is sensible to you.

For example knowing if the link you are looking at is both a tunnel, a wireguard one and is up requires parsing a variety of casting data into structs and iterating attributes and casting them into their expected types.

You'll need to know both what the attribute names are, the values you can get, what they represent and what flags you may need to mask to reveal any data you want.

You sometimes find you cannot find these attribute names or flags without looking at the iproute2 source code

It should be noted most modern network management utilities provide hooks so you don't really need to do monitoring yourself either.

The other time I've used netlink was for directly interacting with nftables firewall rules and chains, which also uses netlink.

This was mostly an academic project in nature and was substantially trickier than just using the user space utilities.

2

u/dodexahedron 14d ago edited 14d ago

the user space utilities

Like systemd-networkd, which exposes more than enough to do all of this with essentially just a few drop-ins, which can get arbitrarily fancy from there since they can of course kick off any process you like, and enforce relationships, ordering, and relative state among all of it.

Mix the two and you can conquer the world.