Prerequisites#
- M13 comfort with processes helps when you ask “who owns this port?” later.
- Outbound HTTPS allowed for the
curllab (most home/cloud defaults allow it).
Learning objectives#
- Print hostname and interface addresses with
hostnameandip. - Read a simple default route.
- Test connectivity with
pingand/orcurl. - List listening TCP ports with
ss. - Resolve a name with
getent hosts(and know thatdig/hostare optional extras).
Lab environment#
mkdir -p /tmp/linux-lab-pushpjeet/m18
cd /tmp/linux-lab-pushpjeet/m18
1. Hostname#
hostname
hostname -f 2>/dev/null || hostname
Lab run: grok-bot-vm-270875175 (your cloud or VM name will differ).
Change only when you know your org’s naming policy (hostnamectl set-hostname on systemd distros — optional reading).
2. Addresses with ip#
The older ifconfig still appears in blog posts; learn ip from the iproute2 suite.
ip -br addr # brief overview
ip addr # full detail
ip route # routing table
Lab run (ip -br addr):
lo UNKNOWN 127.0.0.1/8 ::1/128
enp0s3 UP 172.30.0.2/24 fe80::802b:38ff:fe3d:bcd0/64
docker0 DOWN 172.17.0.1/16
| Piece | Meaning |
|---|---|
lo |
Loopback — always talks to yourself (127.0.0.1) |
enp0s3 |
Example Ethernet-style NIC (name varies) |
172.30.0.2/24 |
IPv4 address and prefix length |
fe80::… |
Link-local IPv6 |
UP / DOWN |
Interface operational state |
Lab default route:
default via 172.30.0.1 dev enp0s3
That via address is your gateway for off-subnet traffic.
Useful extras:
ip -br link # layers 1–2 style summary
ip route get 1.1.1.1 # which path would a packet take?
3. Connectivity: ping and curl#
ping#
ping -c 3 127.0.0.1
ping -c 3 172.30.0.1 # your gateway from ip route
ping -c 3 example.com # DNS + ICMP (may be blocked)
-c 3 sends three probes then stops (important — bare ping runs forever).
Note: Some containers and locked-down images omit ping (iputils-ping / inetutils-ping). On the drafting box it was not installed. Install via M16 if you want it, or use curl below.
curl / wget as reachability checks#
curl -sI --max-time 5 https://example.com | head -5
Lab run:
HTTP/2 200
date: Sat, 26 Sep 2026 05:35:37 GMT
content-type: text/html
server: cloudflare
...
HTTP/2 200 (or HTTP/1.1 200) means TCP+TLS+HTTP to that host worked — stronger proof of “internet useful” than ICMP alone when ping is blocked.
wget -qO- --timeout=5 https://example.com | head -c 100
4. Listening sockets with ss#
netstat is legacy; prefer ss.
ss -tln # TCP listen, numeric ports
ss -uln # UDP listen
ss -tlnp # + process (may need sudo for all names)
Lab sample (ss -tln abridged):
State Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0 128 127.0.0.1:8791 0.0.0.0:*
LISTEN 0 100 0.0.0.0:6080 0.0.0.0:*
| Pattern | Meaning |
|---|---|
127.0.0.1:port |
Listening only on loopback (local clients) |
0.0.0.0:port |
Listening on all IPv4 interfaces |
[::]:port |
IPv6 all-interfaces listener |
When something cannot connect, ask: Is the process listening? On which address? Is a firewall in the way? (Firewalls are a follow-on topic; knowing ss comes first.)
5. DNS quick check#
getent hosts example.com
Lab run (IPv6 answers shown):
2606:4700:10::ac42:93f3 example.com
2606:4700:10::6814:179a example.com
Optional tools (install if needed): host example.com, dig example.com, nslookup example.com.
If curl works by IP but not by name, suspect DNS. If neither works, suspect route/firewall/connectivity.
6. Mini troubleshooting order#
ip -br addr— do I have an address?ip route— is there a default gateway?pinggateway orcurla known site.getent hosts— do names resolve?ss -tln— is my service listening where I expect?
Write that order on a sticky note; it saves hours over random guessing.
Common mistakes#
| Mistake | Fix |
|---|---|
Leaving ping running forever |
Always -c or Ctrl+C |
| Assuming ping failure = “no internet” | ICMP may be blocked; try curl |
| Ignoring interface names | Copy the name from ip -br link exactly |
| Debugging apps before checking listen address | ss -tln — bound to 127.0.0.1 vs 0.0.0.0 matters |
| Mixing up public vs private IPs | 10.x, 172.16–31.x, 192.168.x are private; fine on LAN/VPC |
Hands-on lab (30–45 minutes)#
- Record
hostnameandip -br addrin your notes. - Identify default gateway from
ip route. curl -sI https://example.comand save the status line.ss -tln | headand circle one loopback and one non-loopback listen (if present).getent hosts example.com.- Stretch: Install
iputils-ping(M16) andping -c 3your gateway.
Practice: check your understanding#
Multiple choice#
Q1. Which command shows a brief list of interfaces and IPs on modern Linux?
- A.
chmod -br addr - B.
ip -br addr - C.
tar -br addr - D.
dnf -br addr
Answer: B.
Q2. A line default via 192.168.1.1 dev eth0 means:
- A. eth0 is down
- B. Packets to other networks go via gateway
192.168.1.1oneth0 - C. DNS is disabled
- D. UID 192 is the network owner
Answer: B.
Q3. ss -tln is primarily for:
- A. Creating tar archives
- B. Listing listening TCP sockets
- C. Installing packages
- D. Editing sudoers
Answer: B.
Flashcards#
| Front | Back |
|---|---|
hostname |
This machine’s name |
ip -br addr |
Brief interface + address list |
ip route |
Routing table (find default gateway) |
| Gateway | Next hop for off-subnet traffic |
ping -c 3 |
Three ICMP echoes, then stop |
curl -sI |
Fetch response headers only |
ss -tln |
TCP listening sockets, numeric |
getent hosts |
Name → address via system resolver |
127.0.0.1 |
Loopback IPv4 |
0.0.0.0 listener |
Accept on all IPv4 interfaces |
Match the columns#
| Item | Match |
|---|---|
lo |
Loopback interface |
default via … |
Default route / gateway |
curl -sI |
HTTP(S) headers check |
ss -uln |
UDP listen sockets |
getent hosts |
DNS/hosts lookup |
enp0s3 / eth0 |
Example NIC names |
Fill in the blank#
-
Brief addresses:
ip ___ addr
Answer:-br -
Three pings:
ping ___ 127.0.0.1
Answer:-c 3 -
TCP listeners:
ss ___
Answer:-tln -
Headers from example.com:
curl ___ https://example.com
Answer:-sI(or-I;-ssilences progress)
Order the steps — “why can’t I reach the web?”#
- Check
ip -br addrfor an address on the NIC - Check
ip routefor a default gateway - Probe gateway (
ping) or trycurl -sI https://example.com - If IP works but names fail, check
getent hosts - If your server is unreachable to others, check
ss -tlnand firewall docs
Correct order: 1 → 2 → 3 → 4 → 5
Mini terminal challenges#
Challenge: Show IP and curl#
Goal: Document your address and prove outbound HTTPS.
Tasks:
- Save
hostnameandip -br addrto/tmp/linux-lab-pushpjeet/m18/net-notes.txt. - Append the first status line from
curl -sI https://example.com.
Verify: File contains an interface line and HTTP/… 200 (or another informative status).
Stretch: Append ss -tln | wc -l (how many listen lines?).
Challenge: Gateway identity#
Goal: From ip route, write down the gateway IP and which device it uses.
Verify: ip route get 1.1.1.1 mentions that device (wording varies).
Module wrap#
You can report addresses and routes with ip, probe reachability with ping/curl, list listeners with ss, and resolve names with getent hosts. That completes the Linux from Scratch expansion track through M18.