Network Interface (part 1)

Oct 1, 2026

We can think of network interface as a virtual or physical doorway that allows the computer to speak with the outside world.

1. Physical vs. Virtual Interfaces

Physical:

  • Ethernet Ports (eth0, ens5)
  • Wifi-Cards (wlan0)

Virtual: -> software-defined

  • Loopback (lo): A special virtual interface (usually assigned the IP 127.0.0.1) -> computer uses to talk to itself for testing.
  • Docker/Container Bridges (docker0): isolated applications/containers on the same machine so each one can talk to each other.
  • VPN Tunnels (tun0, tap0, wg0, tailscale0): encrypt data before sending out through a physical interface.

2. Where it sits in the OSI model?

A network interface bridges the gap between Hardware and Software. It operates at 2 layers simutaneously:

  • Physical Layer: software data —> electrial signals/optics/waves.
  • Data Link Layer: it holds the MAC address

3. The relationship: Interface vs. IP Address

Each interface connects to a different network —> each needs its own IP address

Note: one interface can have multiple IP addresses, but an IP address can only belong to one interface at a time

4. Example on an EC2 instance (Linux)

ubuntu@ip-10-0-12-241:~$ ip addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: ens5: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9001 qdisc mq state UP group default qlen 1000
    link/ether 0a:d8:d7:96:47:b5 brd ff:ff:ff:ff:ff:ff
    inet 10.0.12.241/24 metric 100 brd 10.0.12.255 scope global dynamic ens5
       valid_lft 3398sec preferred_lft 3398sec
    inet6 fe80::8d8:d7ff:fe96:47b5/64 scope link
       valid_lft forever preferred_lft forever
3: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 8921 qdisc noqueue state UNKNOWN group default qlen 1000
    link/none
    inet 10.10.0.1/24 scope global wg0
       valid_lft forever preferred_lft forever
6: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
    link/ether e2:d4:a8:ba:b3:14 brd ff:ff:ff:ff:ff:ff
    inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
       valid_lft forever preferred_lft forever
    inet6 fe80::e0d4:a8ff:feba:b314/64 scope link
       valid_lft forever preferred_lft forever
9: tailscale0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1280 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none
    inet6 fe80::d433:a819:9a4c:9448/64 scope link stable-privacy
       valid_lft forever preferred_lft forever
20: br-c086560e0a28: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
    link/ether 56:39:06:71:27:99 brd ff:ff:ff:ff:ff:ff
    inet 172.18.0.1/16 brd 172.18.255.255 scope global br-c086560e0a28
       valid_lft forever preferred_lft forever
    inet6 fe80::5439:6ff:fe71:2799/64 scope link
       valid_lft forever preferred_lft forever
23: vethb54afa7@if2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-c086560e0a28 state UP group default
    link/ether 62:a4:fd:66:c7:ee brd ff:ff:ff:ff:ff:ff link-netnsid 0
    inet6 fe80::60a4:fdff:fe66:c7ee/64 scope link
       valid_lft forever preferred_lft forever
25: wg1: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    link/none
    inet 10.201.2.10/32 scope global wg1
       valid_lft forever preferred_lft forever

From the above example, we can see some interfaces and its IP address: lo - 127.0.0.1, ens5 - 10.0.12.241/24, wg0 - 10.10.0.1/24, wg1 - 10.201.2.10/32 (WireGuard), tailscale0, docker0 - 172.17.0.1/16,…

We can say the ens5 is a Physical interface, but actually the EC2 instance is a VM running on a shared AWS server and the IP address is connected to the AWS VPC.

5. Example on a real Macbook

danieldang@Daniels-M5 scripts % ifconfig
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
	inet 127.0.0.1 netmask 0xff000000
	inet6 ::1 prefixlen 128
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
	nd6 options=201<PERFORMNUD,DAD>
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
	inet6 fe80::c3c4:1d96:5d3:f012%utun0 prefixlen 64 scopeid 0x12
	nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
	inet6 fe80::74e7:8cd7:ef28:9fb8%utun1 prefixlen 64 scopeid 0x13
	nd6 options=201<PERFORMNUD,DAD>
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=6460<TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
	ether c0:c7:db:11:67:9a
	inet6 fe80::1016:a248:abcd:e648%en0 prefixlen 64 secured scopeid 0xf
	inet6 2001:ee0:5004:50c0:1024:1f61:70ad:3d2b prefixlen 64 autoconf secured
	inet6 2001:ee0:5004:50c0:e5e3:3c77:636:4fa8 prefixlen 64 autoconf temporary
	inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255
	nd6 options=201<PERFORMNUD,DAD>
	media: autoselect
	status: active
..

en0 is a physical interface as a Wifi chip, it has inet 192.168.1.2 which is the private address the home router gave to the Mac.

utun interfaces: VPN Tunnels