Symptoms & scope
- NetworkManager says an address is already in use and refuses to configure it.
- An IPv6 address has dadfailed/tentative state or the kernel identifies a duplicate.
Relevant environment
NetworkManager IPv4 address conflict detection or kernel IPv6 DAD; detection defaults depend on the installed manager and distribution.
Recognizable messages (synthetic examples)
NetworkManager[650]: device (enp3s0): IP address 192.0.2.20 cannot be configured because it is already in use in the network by host 02:00:00:00:00:02Correlate the reported peer with authorized address allocation and topology; do not bypass detection.
kernel: IPv6: enp3s0: IPv6 duplicate address 2001:db8::20 used by 02:00:00:00:00:02 detected!Check dadfailed state and subsequent recovery; address conflict or layer-two behavior needs investigation rather than disabling DAD.
Possible causes
These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.
- A static address can overlap another host or a DHCP pool/reservation, or cloned systems can share intended network identity.
- A bridge loop or unexpected neighbor response can also trigger conflict detection; the reported peer MAC and network topology need confirmation.
Diagnose safely
Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.
Check 1
Replace IFACE with the interface named by the conflict. Read IPv4/IPv6 addresses and flags without adding, removing or reprobeing them.
ip address show dev IFACEInterpret the result: dadfailed is an IPv6 conflict result; tentative alone can be a normal short-lived DAD phase. IPv4 may be absent because NetworkManager refused the conflicting address.
Check 2
Read IPv4 conflict events with journal privileges if needed. Preserve the address, interface and reported peer MAC for the network administrator.
journalctl -b -u NetworkManager --no-pager -n 250Interpret the result: The already-in-use message is more specific than ip-config-unavailable. The peer MAC is a lead, not permission to change another host or proof of a malicious response.
Check 3
Read kernel IPv6 duplicate events and their peer address/MAC context; access to the kernel journal may require privileges.
journalctl -k -b --no-pager -n 250Interpret the result: A duplicate detected event means DAD received conflicting evidence. Stable privacy generation may retry a different address; check whether a usable address appeared afterward.
Evidence-guided next steps
Fix confirmed clone identity or a layer-two loop
If conflicts occur only between cloned VMs, inspect their hypervisor MAC assignments and the manager’s DHCP/address-generation identity using the platform’s cloning procedure. If peer evidence indicates a bridge loop instead, remove the confirmed duplicate physical or virtual path with the network administrator.
Precautions: Do not disable DAD/ACD or regenerate every machine identity blindly. Identity changes can affect leases and management access; save the VM and network configuration first.
Recovery / rollback: Restore the saved VM identity or topology if the diagnosis was wrong, then recover the original management path and keep the conflicting interface down while investigating.
Did this solution help you?
References & review
This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.
- NetworkManager: IPv4 method, DNS priorities and address conflict detection (project or distribution documentation)
- Fedora: NetworkManager IPv4 address conflict detection (project or distribution documentation)
- Linux IPv6: duplicate address detection source snapshot (upstream implementation; behavior can vary by version)
- Debian iproute2 manual: ip-neighbour(8) (project or distribution documentation)