Host Networking
One machine's view of the network: its addresses, routes, names and sockets, and how to tell refused from timed out from unresolved.
An interactive Linux lesson: 21 steps, about 35 minutes, on a live simulation in your browser.
You are on call for web01. It serves the shop's website, keeps sessions in a local cache, reads from a database on db01 and ships backups to backup01. Before the first "the site cannot reach X" ticket arrives, learn what this machine knows about the network. It starts with ip addr.
The output is one numbered block per interface, a point where the machine attaches to a network. lo is the loopback: a software interface every Linux machine has, with inet 127.0.0.1/8. Traffic sent there never leaves the machine. Its state UNKNOWN is normal.
What you will learn
Interfaces and addresses
- Two interfaces: lo and eth0: An address belongs to an interface, not to the machine. lo is the machine talking to itself; eth0 is the machine talking to everyone else.
- What the /24 tells the kernel: The /24 tells the kernel who is a neighbour. Same first 24 bits: deliver directly. Anything else: hand it to a router.
Routes and the gateway
- The routing table has two lines: The routing table is a list of destinations and exits. The most specific match wins, and default is the match of last resort.
- Ask the kernel which way
Names on a host
- Two files turn names into addresses: Name resolution on a host is two lookups in order: the local table in /etc/hosts, then the DNS server named in /etc/resolv.conf.
- When /etc/hosts and DNS disagree: Applications read /etc/hosts before DNS. dig and host ask DNS only, so they can be right while your application is wrong.
Who is listening
- ss -tlnp, column by column: A listening socket is an address, a port and the process that owns them. ss -tlnp shows all three for every door into the machine.
- 0.0.0.0 versus 127.0.0.1: 0.0.0.0 means every address this machine has. 127.0.0.1 means loopback only, so only programs on this machine can connect.
Can I reach it
- Three questions: ping, nc, curl: Three questions, in order: is the host there (ping), is the port open (nc -zv), does the application answer (curl -v).
- Break it: the name does not resolve
- Break it: connection refused: Refused means a machine answered no. The host is up and reachable; nothing is listening on that address and port.
- A host that is down: Silence is not refusal. No reply at all means the host is down or something on the path is dropping the packets.
The host firewall
- ufw: closed unless you open it: Default deny: every incoming port is closed unless a rule opens it. A connection needs both a listening socket and a rule that lets it in.
- A peek underneath: iptables -L
- Break it: a rule that drops: Could not resolve: you never sent anything. Refused: a machine answered no. Timed out: nothing answered, because of a dead host or a firewall dropping packets.
- Drill: open a port
When the link goes
- Break it: eth0 goes down: An interface that goes down takes its routes with it. With no route, the kernel fails instantly with Network is unreachable, and every name lookup fails along with it.
- Drill: bring the link back
- One order for every ticket: Follow the packet: interface, route, name, host, port, application. The first check that fails is where the fault is.
Recap & playground
- Cheat sheet
- Playground