Network tools · Network tools

Linux Network Troubleshooting with ip and ss

Before editing a Linux network configuration, inspect the state the kernel is actually using. Interface addresses, route selection and application sockets describe different parts of the path. This sequence keeps those layers visible and avoids a common mistake: changing DNS when the service is listening only on localhost.

Scope: Linux iproute2. All listed commands inspect state; process visibility can require root.

Find the interface and address #

Find the interface and address
Network tools · Local shell; platform and privileges as described below

Read-only
ip -br address show
Read-only

Replace these example values: eth0.

ip -s link show dev eth0
Read-only
ip neighbour show

Replace eth0 with the interface shown on your machine. The brief address view is easier to scan than a full configuration dump. Link statistics provide a baseline for a later comparison. A nonzero lifetime counter is not, by itself, proof of a fault occurring now; capture a second reading during the failing transfer.

Ask the kernel which route it selects #

Ask the kernel which route it selects
Network tools · Local shell; platform and privileges as described below

Read-only
ip route show
Read-only
ip rule show
Read-only

Replace these example values: 192.0.2.20.

ip route get 192.0.2.20
Read-only

Replace these example values: 192.0.2.20, 192.0.2.10.

ip route get 192.0.2.20 from 192.0.2.10
Read-only

Replace these example values: 2001:db8::20.

ip -6 route get 2001:db8::20

Use an actual locally assigned address for the from test. A route lookup reports the selected path without sending a packet to the destination. Inspect the output interface, next hop and source address. On hosts with VPNs, containers or multiple uplinks, the default route alone may not explain the application's path. Policy rules and other routing tables can matter.

Inspect application sockets #

Inspect application sockets
Network tools · Local shell; platform and privileges as described below

Read-only
ss -lnt
Read-only
ss -lnu
Read-only
sudo ss -lntp
Read-only
ss -nt state established
Read-only
ss -nt '( dport = :443 or sport = :443 )'

TCP listeners and UDP sockets are separate views. Numeric output makes the port numbers explicit. Process details may need elevated access. Compare the local bind address: 127.0.0.1 is loopback, while a service bound to a network address is a candidate for remote access. A listener still does not prove that the host firewall allows incoming traffic.

Follow the evidence #

If the destination route is unexpected, investigate routing before the application. If the route looks correct but there is no intended listener, investigate the service. If both look correct, compare a local application request with one from an authorized remote client and capture the failing flow.

Remember that namespaces have their own networking state. Commands on the host can show a different view from commands inside a container. Record where each command ran, the selected source address and the observation time. None of the commands above flushes neighbors, changes routes or restarts networking, so the original evidence remains available.

Sources

Documentation reviewed: 8 October 2026