IP addressing, subnets and NIC teaming for servers
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.
Why this matters
A client can change its address every day and nobody notices. A server cannot. DNS records point at it, firewall rules allow traffic to it, other servers are configured to reach it, and users have it bookmarked. If its address changes unexpectedly, all of those break at once.
So server addressing is about predictability, and about removing the network adapter as a single point of failure. This lesson covers how servers get stable addresses, the addressing basics the exam assumes, combining network adapters, and checking that it all works.
The lesson
Static addresses against DHCP reservations for servers
A server needs an address that does not change. There are two ways to achieve that.
A static address is configured directly on the server. It works even when the DHCP service is down, which is why infrastructure servers, such as the DHCP and DNS servers themselves and domain controllers, should always be static: they cannot depend on services they provide. The risks are typing errors and duplicates, because nothing central checks the address before it is used.
A DHCP reservation is configured on the DHCP server, which always gives the same address to the server's network adapter, identified by its MAC address. Addresses stay under central management and can be changed in one place, but the server depends on DHCP being available when it starts.
In practice, core infrastructure uses static addresses, and many organisations use reservations for the other servers. Either way, the address is chosen deliberately and recorded.
Subnet masks, gateways, and IPv4 and IPv6 side by side
An IPv4 address is 32 bits, written as four decimal numbers. The subnet mask divides it into a network part and a host part. A mask of 255.255.255.0, written in CIDR notation as /24, leaves eight bits for hosts: 256 addresses, of which 254 are usable, because the first is the network address and the last the broadcast address.
The default gateway is the router a server uses to reach any address outside its own subnet, and it must be inside that subnet. A server with the wrong gateway can talk to its neighbours but nothing beyond them, which is a common troubleshooting scenario.
Internal networks use the private ranges: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. An address beginning 169.254 is a warning sign: it is an automatically assigned link-local address that a machine gives itself when it expected DHCP and got no answer.
IPv6 addresses are 128 bits, written in hexadecimal groups separated by colons, with runs of zeros shortened to a double colon. Subnets are normally /64. Every IPv6 interface has a link-local address beginning fe80, usable only on its own network segment, alongside its global addresses, which can be assigned automatically (SLAAC), by DHCPv6, or statically. The loopback address is ::1, the equivalent of IPv4's 127.0.0.1. Most servers now run dual stack, with both IPv4 and IPv6 configured, and both need the same care over addressing and firewall rules.
NIC teaming and bonding: failover against aggregation
A server with two or more network adapters can combine them into a single logical adapter with one IP address. Windows calls this NIC teaming, with a variant called Switch Embedded Teaming for Hyper-V hosts; Linux calls it bonding. Teaming serves two different goals, and the configuration depends on which one you want.
Failover, also called active-backup or active/standby, sends traffic over one adapter and keeps the other in reserve. If the active adapter, its cable or its switch port fails, the standby takes over. It needs no special configuration on the switches, so the two adapters can be connected to two different switches, which protects against a switch failure too.
Aggregation uses several adapters at once for more total bandwidth. The standard method is LACP (IEEE 802.3ad, now 802.1AX), which must also be configured on the switch, and which requires the adapters to connect to the same switch or to a stack of switches designed to act as one. Two limits catch people out. Aggregation usually balances by connection, so any single connection still runs at the speed of one adapter; four 1 Gbps adapters give many clients 4 Gbps in total, not one client 4 Gbps. And an LACP team on one switch still has that switch as a single point of failure.
Choose by the problem: failover across two switches for resilience, aggregation for total throughput, or a switch stack that supports both.
Checking the configuration with ipconfig, ip, ping and traceroute
After configuring an address, verify it rather than assume it.
- ipconfig /all on Windows shows each adapter's address, mask, gateway, DNS servers, MAC address and DHCP lease details.
- ip addr and ip route on Linux show addresses and the routing table, including the default gateway. The older ifconfig command is deprecated.
- ping tests whether another host answers. A failed ping does not prove the host is down, because firewalls often block ping; a successful one proves it is reachable.
- tracert on Windows and traceroute on Linux show each router on the path to a destination, so you can see where traffic stops.
Test outwards in a sensible order: the loopback address, then the server's own address, then the default gateway, then a host on another network, and finally a name rather than an address. Where the sequence first fails tells you where to look: a failure at the gateway points to addressing or cabling, while addresses that work and names that do not point to DNS, which the next lesson covers.
Recording addresses so the next change does not collide
Two devices with the same address cause address conflicts: intermittent connectivity for both, warnings in the operating system, and faults that are maddening to trace because they come and go.
The prevention is to keep an authoritative record of every static address and reservation, in an IP address management (IPAM) tool or, at smaller scale, a controlled spreadsheet. Record the address, the hostname, the MAC address, the VLAN and the purpose. Before assigning a new address, check the record, check the DHCP scopes to make sure it is outside the range DHCP hands out, and check that nothing already answers on it. After assigning it, update the record straight away.
An address record that is out of date is worse than none, because people trust it. Keeping it current is part of the job, not paperwork after it.
Try it
An interactive exercise runs here: a real Linux machine in your browser that checks each step. The commands above work on any Linux machine too.
Practise what you just read
1. A server has address 10.1.4.20/22. Which address is in the same subnet?
Select one
Show answer
D. A /22 covers four third-octet values aligned to a multiple of four. 10.1.4.20 falls in 10.1.4.0 to 10.1.7.255, so 10.1.7.200 is in it; 10.1.8.20 and 10.1.3.20 are in neighbouring subnets.
2. A server can reach every host on its own subnet but nothing beyond it. What is most likely wrong?
Select one
Show answer
A. Local communication does not use the gateway, so local success with remote failure points directly at a missing or wrong default gateway. DNS faults affect names, not addresses.
3. What is the main benefit of an active-backup NIC team?
Select one
Show answer
C. In active-backup, one adapter carries traffic and the other takes over if the first fails. It adds no throughput but works with any switch, which makes it the simplest form of redundancy.
7 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA Server+ SK0-005 course — 51 lessons and 72 hands-on labs.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.