Configure Network Bonding for Redundancy on CentOS
Network bonding joins two or more physical network interfaces into one logical link. On CentOS, this can keep a server reachable when a cable, network adapter, or switch port fails. Bonding is useful for web servers, database hosts, virtualisation nodes, and storage systems where a brief network interruption is costly.
Australian administrators commonly use redundant links in Sydney and Melbourne colocation facilities, as well as smaller server rooms in Brisbane and Perth. The design should match the switch configuration, the CentOS release, and the organisation’s security requirements, including controls influenced by the Australian Privacy Act 1988 and the Essential Eight.
Choose the right bonding mode
The active-backup mode is usually the safest starting point. One interface carries traffic while the second waits as a standby. It requires little switch configuration and provides failover if the active cable, NIC, or switch port stops working.
Link aggregation modes such as 802.3ad, also called LACP, can use multiple links at once. They require compatible configuration on the switch, and the switch must normally place both ports in the same bonded channel. A mismatch can cause packet loss or unstable connectivity rather than improving resilience.
Check interfaces and network details
List the available interfaces before changing configuration:
ip link show
nmcli device status
lspci | grep -i ethernet
Record the interface names, current IP address, default gateway, DNS servers, and switch port assignments. Modern CentOS systems may use names such as ens160 or enp1s0; do not assume they are eth0 and eth1.
Keep a console connection available during the change. If the server is remote, arrange out-of-band access through a management controller or a provider console. This is particularly important in Australian colocation environments, where a failed remote network change may require a technician to access the rack.
For broader command-line reference material, the Linux Unix guides provide related administration topics that complement interface and service troubleshooting.
Create a bond with NetworkManager
NetworkManager is the preferred method on current CentOS installations. The following example creates an active-backup bond using enp1s0 and enp2s0:
sudo nmcli con add type bond ifname bond0 con-name bond0 \
bond.options "mode=active-backup,miimon=100"
sudo nmcli con add type ethernet ifname enp1s0 \
con-name bond0-slave1 master bond0
sudo nmcli con add type ethernet ifname enp2s0 \
con-name bond0-slave2 master bond0
Assign the server’s address to the bond, not to either physical interface. Replace the example values with the correct address for the host:
sudo nmcli con mod bond0 \
ipv4.method manual \
ipv4.addresses 192.0.2.20/24 \
ipv4.gateway 192.0.2.1 \
ipv4.dns "192.0.2.53 1.1.1.1" \
ipv6.method disabled
sudo nmcli con up bond0
The miimon=100 setting checks link status every 100 milliseconds. It detects a physical link failure quickly, although it may not detect every upstream switching problem. Keep the member interfaces free of separate IP addresses and avoid defining competing default gateways.
Configure LACP when required
For active-active bandwidth and switch-managed aggregation, create the bond with LACP settings:
sudo nmcli con add type bond ifname bond0 con-name bond0 \
bond.options "mode=802.3ad,miimon=100,lacp_rate=fast,xmit_hash_policy=layer3+4"
The switch ports must be configured as one LACP group, with matching VLAN membership, native VLAN rules, speed, and duplex settings. A server connected to two unrelated switches cannot use ordinary LACP unless the switching platform supports a multi-chassis aggregation feature.
If the server hosts a MariaDB workload, network redundancy should be tested alongside database recovery procedures; the MariaDB on Fedora guide offers useful installation context even when the production host uses CentOS.
Test failover and inspect faults
Confirm the bond state and active member:
cat /proc/net/bonding/bond0
nmcli connection show
ip addr show bond0
ip route
Test from another host with continuous ping, then disconnect the active cable or disable its switch port. Traffic should continue through the backup interface. Restore the link and verify whether the bond returns to the preferred member.
Useful diagnostics include:
journalctl -u NetworkManager -b
nmcli device show bond0
ethtool enp1s0
ip -s link show bond0
A bond does not protect against every failure. It cannot compensate for a failed gateway, an incorrect VLAN, a dead switch stack, or a firewall rule blocking the traffic. Australian businesses aligning systems with the Essential Eight should also monitor link changes, retain relevant logs, and document who can alter switch and host networking.
Compare practical bonding options
The right mode depends on switch support, the failure scenario, and whether extra throughput matters. A simple failover design is often easier to operate than a more complex aggregation arrangement.
When infrastructure documentation covers both Linux services and a content platform, a reference about a custom WordPress block can sit alongside the server runbook, provided access credentials and network diagrams remain protected.
| Mode | Traffic use | Switch configuration | Best fit |
|---|---|---|---|
active-backup |
One link at a time | Usually none | Reliable failover with simple operations |
balance-xor |
Distributed by hash | Often required | Controlled static aggregation |
802.3ad |
LACP-based distribution | Required | Redundant links with compatible switches |
balance-alb |
Adaptive transmit and receive balancing | Usually none | Selected environments without LACP |
The main principle is simple: place the IP configuration on bond0, make the switch and host agree on the bonding mode, and test a real cable or port failure before relying on redundancy.