← Linux from ScratchCheat sheet
M18Linux from Scratch

M18 — Networking basics for admins

Time: about 40–60 minutes
Lab root: /tmp/linux-lab-pushpjeet/m18

You do not need to be a network engineer to administer a Linux box — but you do need to answer: What is my address? Can I reach the gateway? Can I reach the internet? Is anything listening on this port? This module gives you those checks with modern tools (ip, ss, curl) plus classic ping when it is installed.

Generic Linux. Interface names vary (eth0, ens5, enp0s3, wlan0).

Prerequisites#

  • M13 comfort with processes helps when you ask “who owns this port?” later.
  • Outbound HTTPS allowed for the curl lab (most home/cloud defaults allow it).

Learning objectives#

  1. Print hostname and interface addresses with hostname and ip.
  2. Read a simple default route.
  3. Test connectivity with ping and/or curl.
  4. List listening TCP ports with ss.
  5. Resolve a name with getent hosts (and know that dig/host are optional extras).

Lab environment#

mkdir -p /tmp/linux-lab-pushpjeet/m18
cd /tmp/linux-lab-pushpjeet/m18

1. Hostname#

hostname
hostname -f 2>/dev/null || hostname

Lab run: grok-bot-vm-270875175 (your cloud or VM name will differ).
Change only when you know your org’s naming policy (hostnamectl set-hostname on systemd distros — optional reading).


2. Addresses with ip#

The older ifconfig still appears in blog posts; learn ip from the iproute2 suite.

ip -br addr          # brief overview
ip addr              # full detail
ip route             # routing table

Lab run (ip -br addr):

lo               UNKNOWN        127.0.0.1/8 ::1/128
enp0s3           UP             172.30.0.2/24 fe80::802b:38ff:fe3d:bcd0/64
docker0          DOWN           172.17.0.1/16
Piece Meaning
lo Loopback — always talks to yourself (127.0.0.1)
enp0s3 Example Ethernet-style NIC (name varies)
172.30.0.2/24 IPv4 address and prefix length
fe80::… Link-local IPv6
UP / DOWN Interface operational state

Lab default route:

default via 172.30.0.1 dev enp0s3

That via address is your gateway for off-subnet traffic.

Useful extras:

ip -br link          # layers 1–2 style summary
ip route get 1.1.1.1 # which path would a packet take?

3. Connectivity: ping and curl#

ping#

ping -c 3 127.0.0.1
ping -c 3 172.30.0.1          # your gateway from ip route
ping -c 3 example.com         # DNS + ICMP (may be blocked)

-c 3 sends three probes then stops (important — bare ping runs forever).

Note: Some containers and locked-down images omit ping (iputils-ping / inetutils-ping). On the drafting box it was not installed. Install via M16 if you want it, or use curl below.

curl / wget as reachability checks#

curl -sI --max-time 5 https://example.com | head -5

Lab run:

HTTP/2 200
date: Sat, 26 Sep 2026 05:35:37 GMT
content-type: text/html
server: cloudflare
...

HTTP/2 200 (or HTTP/1.1 200) means TCP+TLS+HTTP to that host worked — stronger proof of “internet useful” than ICMP alone when ping is blocked.

wget -qO- --timeout=5 https://example.com | head -c 100

4. Listening sockets with ss#

netstat is legacy; prefer ss.

ss -tln          # TCP listen, numeric ports
ss -uln          # UDP listen
ss -tlnp         # + process (may need sudo for all names)

Lab sample (ss -tln abridged):

State  Recv-Q Send-Q Local Address:Port  Peer Address:Port
LISTEN 0      128        127.0.0.1:8791       0.0.0.0:*
LISTEN 0      100          0.0.0.0:6080       0.0.0.0:*
Pattern Meaning
127.0.0.1:port Listening only on loopback (local clients)
0.0.0.0:port Listening on all IPv4 interfaces
[::]:port IPv6 all-interfaces listener

When something cannot connect, ask: Is the process listening? On which address? Is a firewall in the way? (Firewalls are a follow-on topic; knowing ss comes first.)


5. DNS quick check#

getent hosts example.com

Lab run (IPv6 answers shown):

2606:4700:10::ac42:93f3 example.com
2606:4700:10::6814:179a example.com

Optional tools (install if needed): host example.com, dig example.com, nslookup example.com.

If curl works by IP but not by name, suspect DNS. If neither works, suspect route/firewall/connectivity.


6. Mini troubleshooting order#

  1. ip -br addr — do I have an address?
  2. ip route — is there a default gateway?
  3. ping gateway or curl a known site.
  4. getent hosts — do names resolve?
  5. ss -tln — is my service listening where I expect?

Write that order on a sticky note; it saves hours over random guessing.


Common mistakes#

Mistake Fix
Leaving ping running forever Always -c or Ctrl+C
Assuming ping failure = “no internet” ICMP may be blocked; try curl
Ignoring interface names Copy the name from ip -br link exactly
Debugging apps before checking listen address ss -tln — bound to 127.0.0.1 vs 0.0.0.0 matters
Mixing up public vs private IPs 10.x, 172.16–31.x, 192.168.x are private; fine on LAN/VPC

Hands-on lab (30–45 minutes)#

  1. Record hostname and ip -br addr in your notes.
  2. Identify default gateway from ip route.
  3. curl -sI https://example.com and save the status line.
  4. ss -tln | head and circle one loopback and one non-loopback listen (if present).
  5. getent hosts example.com.
  6. Stretch: Install iputils-ping (M16) and ping -c 3 your gateway.

Practice: check your understanding#

Multiple choice#

Q1. Which command shows a brief list of interfaces and IPs on modern Linux?

  • A. chmod -br addr
  • B. ip -br addr
  • C. tar -br addr
  • D. dnf -br addr

Answer: B.

Q2. A line default via 192.168.1.1 dev eth0 means:

  • A. eth0 is down
  • B. Packets to other networks go via gateway 192.168.1.1 on eth0
  • C. DNS is disabled
  • D. UID 192 is the network owner

Answer: B.

Q3. ss -tln is primarily for:

  • A. Creating tar archives
  • B. Listing listening TCP sockets
  • C. Installing packages
  • D. Editing sudoers

Answer: B.

Flashcards#

Front Back
hostname This machine’s name
ip -br addr Brief interface + address list
ip route Routing table (find default gateway)
Gateway Next hop for off-subnet traffic
ping -c 3 Three ICMP echoes, then stop
curl -sI Fetch response headers only
ss -tln TCP listening sockets, numeric
getent hosts Name → address via system resolver
127.0.0.1 Loopback IPv4
0.0.0.0 listener Accept on all IPv4 interfaces

Match the columns#

Item Match
lo Loopback interface
default via … Default route / gateway
curl -sI HTTP(S) headers check
ss -uln UDP listen sockets
getent hosts DNS/hosts lookup
enp0s3 / eth0 Example NIC names

Fill in the blank#

  1. Brief addresses: ip ___ addr
    Answer: -br

  2. Three pings: ping ___ 127.0.0.1
    Answer: -c 3

  3. TCP listeners: ss ___
    Answer: -tln

  4. Headers from example.com: curl ___ https://example.com
    Answer: -sI (or -I; -s silences progress)

Order the steps — “why can’t I reach the web?”#

  1. Check ip -br addr for an address on the NIC
  2. Check ip route for a default gateway
  3. Probe gateway (ping) or try curl -sI https://example.com
  4. If IP works but names fail, check getent hosts
  5. If your server is unreachable to others, check ss -tln and firewall docs

Correct order: 1 → 2 → 3 → 4 → 5

Mini terminal challenges#

Challenge: Show IP and curl#

Goal: Document your address and prove outbound HTTPS.

Tasks:

  1. Save hostname and ip -br addr to /tmp/linux-lab-pushpjeet/m18/net-notes.txt.
  2. Append the first status line from curl -sI https://example.com.

Verify: File contains an interface line and HTTP/… 200 (or another informative status).

Stretch: Append ss -tln | wc -l (how many listen lines?).

Challenge: Gateway identity#

Goal: From ip route, write down the gateway IP and which device it uses.

Verify: ip route get 1.1.1.1 mentions that device (wording varies).


Module wrap#

You can report addresses and routes with ip, probe reachability with ping/curl, list listeners with ss, and resolve names with getent hosts. That completes the Linux from Scratch expansion track through M18.


Continue

← Linux from Scratch hub · Cheat sheet · All tutorials