ethtool: network interface diagnostics and tuning
Network issues hide well — interface is up, IP is assigned, iptables is quiet, yet packet loss or micro-freezes only surface under load. ethtool gives direct access to hardware state, driver behavior, and offload mechanisms that neither ip nor netstat expose.
Basic Output: Link State
Installation is straightforward:
Running ethtool without flags prints a summary:
First thing I check when network complaints come in — Link detected. If no, cable or transceiver is dead. Speed and Duplex tell you whether the link dropped to 100Mb/s or half-duplex.
Driver and Hardware: -i and -a
-i shows driver information:
Firmware version matters for Intel and Broadcom — older versions have known bugs. If you do not see error counters you expect, update firmware first, not the driver.
-a displays auto-negotiation and pause settings:
Disabling flow control on one end of a link without agreement on the other causes packet loss during bursty traffic. If the switch has PAUSE disabled — disable it on the host too.
Speed and Duplex: -s and autoneg
-s changes interface parameters. To set fixed speed and duplex, disable auto-negotiation first, then specify the values:
After changing parameters, verify the link again — not all cards re-negotiate cleanly without an interface bounce.
| ethtool flag | Purpose |
|---|---|
speed N | Speed in Mb/s (100, 1000, 10000, …) |
duplex full|half | Duplex mode |
autoneg on|off | Auto-negotiation control |
port tp|fiber|aui|bnc|mii | Port type (not available on all cards) |
advertise N | Bitmask of modes for auto-negotiation |
All flags combine in a single call. Persisting across reboots requires writing to /etc/sysconfig/network-scripts/ifcfg-eth0 on RHEL or using a systemd override:
Offload Flags: -k, -K and Common Pitfalls
-k shows current offload flags, -K modifies them:
The [fixed] label means the flag is hardware-enforced and cannot be changed.
Disabling offload flags is a frequent cause of VPN, monitoring, and virtualization issues:
GRO (generic-receive-offload) and TSO (tcp-segment-offload) work as a pair. Disabling one without the other causes fragmentation at the kernel level — CPU usage spikes for no good reason.
Statistics: -S and Packet Loss Investigation
-S outputs driver statistics. Format and available counters vary by driver:
For Intel drivers (ixgbe, i40e), relevant counters include:
rx_fifo_errors and tx_fifo_errors indicate congestion. If they grow despite normal CPU utilization, the problem lies with memory or the bus.
For scripted problem detection:
Run periodically via cron — peak loss spikes become impossible to explain retroactively.
Comparison with ip link: What ethtool Covers
| Task | ip link | ethtool |
|---|---|---|
| Bring interface up/down | ip link set eth0 up/down | no |
| MAC address | ip link show eth0 | no |
| MTU | ip link set eth0 mtu 9000 | no |
| Speed/duplex | no | ethtool -s eth0 speed 1000 duplex full |
| Auto-negotiation | no | ethtool -s eth0 autoneg off |
| Offload flags | partially via ethtool -k | ethtool -K eth0 tso off |
| Error statistics | ip -s link show eth0 | ethtool -S eth0 (more detailed) |
| Driver information | no | ethtool -i eth0 |
| Wake-on-LAN | no | ethtool eth0 (shown in output) |
ethtool does not replace ip, it complements it. Network configuration stack: ip link → ip addr → ethtool → tc.
Troubleshooting: Link/Duplex Mismatch
Classic scenario: server and switch failed to agree on parameters. Symptoms — link is up, pings work, but under load there are sudden drops.
Diagnostic sequence:
Always negotiate both ends. If the switch runs fixed mode without autoneg and the host has autoneg enabled — the 802.3 standard mandates fallback behavior, but vendors implement it poorly.
If the interface still drops packets after parameter alignment, investigate:
- Driver and firmware: update the network card firmware
- Cable or transceiver: a 10G SFP module plugged into a 1G port without auto-negotiation guarantees loss
- RSS and IRQ issues:
cat /proc/interrupts | grep eth0, check IRQ balancing