Updated: 28 September 2026 · Applies to: Self-managed dedicated servers on AlmaLinux and Rocky Linux 9

AlmaLinux, Rocky Linux and other Red Hat based systems use NetworkManager. You add extra IPv4 addresses to the connection of your network card with the nmcli command. This guide covers extra addresses that use your main gateway (for example on a plan that includes 5 usable addresses) and an additional subnet with its own gateway, for which traffic from the new addresses must leave through that gateway (source-based routing). The changes are saved and survive a restart.

Before you start

  1. Log in as root or with sudo. Keep the IPMI console at hand (How to get started with Console Redirection of an out-of-band-management?) so that you can recover from a mistake.
  2. Have the details from the delivery message ready: the addresses, the prefix of the block and the gateway of the block (How to order an additional IPv4 subnet for your dedicated server?, How many IP addresses come with a dedicated server and what do additional subnets cost?).

1. Find the connection

nmcli connection show
nmcli -f NAME,DEVICE,TYPE connection show --active
ip -br address

Note the name of the active connection of your network card, for example eno1 or System eno1. Use quotes if the name contains a space.

2. Extra addresses that use your main gateway

The plus sign before ipv4.addresses is important: it adds to the existing addresses. Without it the command replaces them and you lose your connection.

sudo nmcli connection modify "eno1" +ipv4.addresses 203.0.113.11/29
sudo nmcli connection modify "eno1" +ipv4.addresses 203.0.113.12/29
sudo nmcli connection up "eno1"

3. An additional subnet with its own gateway

Example for the block 198.51.100.0/26 with the gateway 198.51.100.1 (replace with your values). The addresses are added to the same connection. The block's default route goes into its own routing table (100), and a routing rule sends traffic from the block's addresses to that table:

sudo nmcli connection modify "eno1" +ipv4.addresses 198.51.100.10/26
sudo nmcli connection modify "eno1" +ipv4.addresses 198.51.100.11/26
sudo nmcli connection modify "eno1" +ipv4.routes "0.0.0.0/0 198.51.100.1 table=100"
sudo nmcli connection modify "eno1" +ipv4.routing-rules "priority 100 from 198.51.100.0/26 table 100"
sudo nmcli connection up "eno1"
  • table=100 is a route attribute: the route is added to table 100 instead of the main table.
  • In ipv4.routing-rules the syntax is the same as in the ip rule add command, but a priority is always required. A lower number means a higher priority.
  • Your main address keeps using the main gateway.

Several subnets: use one table for each (101, 102 and so on), each with its own route to that subnet's gateway and its own rule. For addresses from different subnets this means one table= route and one rule per subnet.

4. Apply and check

ip -br address
ip rule show
ip route show table 100
ip route

Applying can interrupt your SSH session for a moment. All addresses must be listed, ip rule show must show from 198.51.100.0/26 lookup 100, table 100 must contain default via 198.51.100.1, and the main default route must still point to the main gateway. Then test every address: How to test that every additional IP address works on your server?.

Remove an address, route or rule

sudo nmcli connection modify "eno1" -ipv4.addresses 198.51.100.11/26
sudo nmcli connection modify "eno1" -ipv4.routes "0.0.0.0/0 198.51.100.1 table=100"
sudo nmcli connection modify "eno1" -ipv4.routing-rules "priority 100 from 198.51.100.0/26 table 100"
sudo nmcli connection up "eno1"

If something goes wrong

  • You replaced the address by mistake: use the IPMI console and set the main address again with sudo nmcli connection modify "eno1" ipv4.addresses 203.0.113.10/29 ipv4.gateway 203.0.113.9 ipv4.method manual (with your values), then nmcli connection up "eno1". Add the other addresses again afterwards.
  • The block's addresses answer, but outgoing traffic uses the main address: the routing rule is missing or the from does not match the block.
  • The extra addresses do not answer from outside: firewalld may block them (How to write firewall rules for a server with many IP addresses?), or the prefix length is wrong.
  • Older network scripts: if the server uses the legacy network-scripts instead of NetworkManager, these commands do not apply. Check with systemctl status NetworkManager.

Frequently asked questions

Are the settings permanent?
Yes. nmcli connection modify writes them to the connection profile.

Can Ucartz configure it for me?
Yes. Free Basic Managed Support helps with quick checks (best effort), and our engineers can do the full configuration by the task, which is useful for orders with several different subnets.

Source: Red Hat Enterprise Linux 9: Configuring and managing networking (static routes and policy-based routing).

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)