Every DevOps engineer debugs network issues. These are the commands and concepts you need when something cannot connect.
IP Addressing
# Show all interfaces
ip addr show
ip a # Short form
# Show specific interface
ip addr show eth0
# Add/remove IP
sudo ip addr add 10.0.0.10/24 dev eth0
sudo ip addr del 10.0.0.10/24 dev eth0
# Bring interface up/down
sudo ip link set eth0 up
sudo ip link set eth0 downDNS
# Resolve hostname
dig example.com
dig +short example.com
dig example.com MX # Mail records
dig example.com NS # Nameservers
dig @8.8.8.8 example.com # Query specific DNS server
# Reverse lookup
dig -x 93.184.216.34
# Check DNS resolution chain
dig +trace example.com
# Simple lookup
host example.com
nslookup example.com
# Check local DNS config
cat /etc/resolv.conf
# Flush DNS cache (systemd-resolved)
sudo resolvectl flush-cachesConnectivity Testing
# Basic ping
ping -c 4 example.com
# TCP port test
nc -zv example.com 443 # Netcat
curl -v telnet://example.com:5432 # Curl
# HTTP test
curl -I https://example.com # Headers only
curl -w "%{http_code}" -o /dev/null -s https://example.com # Status code
curl -w "DNS: %{time_namelookup}s\nConnect: %{time_connect}s\nTLS: %{time_appconnect}s\nTotal: %{time_total}s\n" -o /dev/null -s https://example.com
# Traceroute
traceroute example.com
mtr example.com # Continuous tracerouteMaster this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āPorts and Connections
# What's listening?
ss -tlnp # TCP listening ports with process
ss -ulnp # UDP listening
ss -tnp # Active TCP connections
# Specific port
ss -tlnp | grep :3000
# All connections to a host
ss -tnp dst 10.0.0.5
# Connection count by state
ss -s
# Legacy (still useful)
netstat -tlnpFirewall (iptables / nftables)
UFW (Ubuntu)
sudo ufw status verbose
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow from 10.0.0.0/8 to any port 5432
sudo ufw deny 23/tcp
sudo ufw enableiptables
# List rules
sudo iptables -L -n -v
sudo iptables -L -n -v -t nat # NAT table
# Allow port
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
# Block IP
sudo iptables -A INPUT -s 192.168.1.100 -j DROP
# Port forwarding
sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 3000
# Save rules
sudo iptables-save > /etc/iptables/rules.v4firewalld (RHEL/CentOS)
sudo firewall-cmd --list-all
sudo firewall-cmd --add-service=http --permanent
sudo firewall-cmd --add-port=3000/tcp --permanent
sudo firewall-cmd --reloadRouting
# Show routing table
ip route show
ip route get 8.8.8.8 # How to reach a specific IP
# Add route
sudo ip route add 10.1.0.0/16 via 10.0.0.1 dev eth0
# Default gateway
sudo ip route add default via 10.0.0.1Packet Capture
# Capture all traffic on interface
sudo tcpdump -i eth0
# Filter by host
sudo tcpdump -i eth0 host 10.0.0.5
# Filter by port
sudo tcpdump -i eth0 port 443
sudo tcpdump -i eth0 'port 80 or port 443'
# Save to file (open in Wireshark)
sudo tcpdump -i eth0 -w capture.pcap -c 1000
# DNS queries
sudo tcpdump -i eth0 port 53
# Show packet contents
sudo tcpdump -i eth0 -A port 80 | head -50Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āNetwork Namespaces (Containers)
# List network namespaces
ip netns list
# Execute in namespace
sudo ip netns exec my-ns ip addr show
# Find container's network namespace
PID=$(docker inspect -f '{{.State.Pid}}' my-container)
sudo nsenter -t $PID -n ip addr show
sudo nsenter -t $PID -n ss -tlnpTroubleshooting Flowchart
Can't connect to service?
āāā Is DNS resolving? ā dig hostname
ā āāā No ā Check /etc/resolv.conf, DNS server
āāā Is the port open? ā nc -zv host port
ā āāā No ā Check firewall (ufw/iptables), service running?
āāā Is the service listening? ā ss -tlnp | grep port
ā āāā No ā Service crashed or wrong bind address
āāā Can you reach the host? ā ping host
ā āāā No ā Check routing (ip route), firewall, security groups
āāā Is there packet loss? ā mtr host
āāā Yes ā Network congestion, ISP issueCommon Issues
| Symptom | Check | Fix |
|---|---|---|
| Connection refused | ss -tlnp | Service not running or wrong port |
| Connection timeout | ping, firewall | Firewall blocking, wrong IP/route |
| DNS not resolving | /etc/resolv.conf | Wrong nameserver, DNS down |
| Intermittent failures | mtr | Packet loss, flaky network |
| High latency | curl -w timing | DNS slow, route inefficient, TLS overhead |
What's Next?
Our Docker Fundamentals course covers container networking. SELinux for System Admins teaches network access controls at the OS level. First lessons are free. -e ---
Ready to go deeper? Explore our hands-on DevOps courses ā practical labs covering Docker, Ansible, Terraform, and more.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Linux Cron Jobs Complete Guide
Master Linux cron jobs for scheduling. Crontab syntax, common patterns, error handling, output logging, and systemd timer alternatives.
Linux Process Management Guide
Manage Linux processes. ps, top, kill signals, background jobs, nice priorities, systemd services, and zombie process cleanup.
Linux File Permissions Explained
Master Linux file permissions. chmod, chown, umask, SUID, SGID, sticky bit, and ACLs with practical examples for system security.
Linux Package Managers Compared
apt, dnf, pacman, zypper, apk ā every major Linux package manager explained with examples. Know which one your distro uses and why.
Linux Security Distros Compared
Kali Linux, Parrot OS, and Tails ā security-focused Linux distributions for penetration testing, privacy, and digital forensics explained.
Local Kubernetes with Kind
Step-by-step guide to creating a local Kubernetes cluster using Kind for ML model development and testing before deploying to production.
Explore topics
Browse more articles on the topics covered here.