Networking, DNS & Wi-Fi

IPv4 conflict or IPv6 duplicate address detection

Resolve confirmed address conflicts when activation is refused or an IPv6 address remains unusable, retaining conflict detection instead of bypassing it.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • NetworkManager says an address is already in use and refuses to configure it.
  • An IPv6 address has dadfailed/tentative state or the kernel identifies a duplicate.

Relevant environment

NetworkManager IPv4 address conflict detection or kernel IPv6 DAD; detection defaults depend on the installed manager and distribution.

Recognizable messages (synthetic examples)
NetworkManager[650]: device (enp3s0): IP address 192.0.2.20 cannot be configured because it is already in use in the network by host 02:00:00:00:00:02

Correlate the reported peer with authorized address allocation and topology; do not bypass detection.

kernel: IPv6: enp3s0: IPv6 duplicate address 2001:db8::20 used by 02:00:00:00:00:02 detected!

Check dadfailed state and subsequent recovery; address conflict or layer-two behavior needs investigation rather than disabling DAD.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • A static address can overlap another host or a DHCP pool/reservation, or cloned systems can share intended network identity.
  • A bridge loop or unexpected neighbor response can also trigger conflict detection; the reported peer MAC and network topology need confirmation.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Replace IFACE with the interface named by the conflict. Read IPv4/IPv6 addresses and flags without adding, removing or reprobeing them.

ip address show dev IFACE

Interpret the result: dadfailed is an IPv6 conflict result; tentative alone can be a normal short-lived DAD phase. IPv4 may be absent because NetworkManager refused the conflicting address.

Check 2

Read IPv4 conflict events with journal privileges if needed. Preserve the address, interface and reported peer MAC for the network administrator.

journalctl -b -u NetworkManager --no-pager -n 250

Interpret the result: The already-in-use message is more specific than ip-config-unavailable. The peer MAC is a lead, not permission to change another host or proof of a malicious response.

Check 3

Read kernel IPv6 duplicate events and their peer address/MAC context; access to the kernel journal may require privileges.

journalctl -k -b --no-pager -n 250

Interpret the result: A duplicate detected event means DAD received conflicting evidence. Stable privacy generation may retry a different address; check whether a usable address appeared afterward.

Evidence-guided next steps

Correct the conflicting address allocation

If the peer and allocation records confirm a duplicate, have the address owner or DHCP administrator assign a free approved address or repair the overlapping reservation/pool. Update only the affected local profile and verify normal conflict detection succeeds afterward.

Precautions: Record the old address, routes and DNS; address changes interrupt sessions and may affect allowlists or service bindings. Do not use an arbitrary unused-looking IP.

Recovery / rollback: Restore the saved profile through local access if the replacement breaks routing, but leave the confirmed duplicate disconnected until allocation is resolved.

Did this solution help you?

Share this solution#

Fix confirmed clone identity or a layer-two loop

If conflicts occur only between cloned VMs, inspect their hypervisor MAC assignments and the manager’s DHCP/address-generation identity using the platform’s cloning procedure. If peer evidence indicates a bridge loop instead, remove the confirmed duplicate physical or virtual path with the network administrator.

Precautions: Do not disable DAD/ACD or regenerate every machine identity blindly. Identity changes can affect leases and management access; save the VM and network configuration first.

Recovery / rollback: Restore the saved VM identity or topology if the diagnosis was wrong, then recover the original management path and keep the conflicting interface down while investigating.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.