Find the interface and address #
Find the interface and address
Network tools · Local shell; platform and privileges as described below
ip -br address showReplace these example values: eth0.
ip -s link show dev eth0ip neighbour showReplace eth0 with the interface shown on your machine. The brief address view is easier to scan than a full configuration dump. Link statistics provide a baseline for a later comparison. A nonzero lifetime counter is not, by itself, proof of a fault occurring now; capture a second reading during the failing transfer.
Ask the kernel which route it selects #
Ask the kernel which route it selects
Network tools · Local shell; platform and privileges as described below
ip route showip rule showReplace these example values: 192.0.2.20.
ip route get 192.0.2.20Replace these example values: 192.0.2.20, 192.0.2.10.
ip route get 192.0.2.20 from 192.0.2.10Replace these example values: 2001:db8::20.
ip -6 route get 2001:db8::20Use an actual locally assigned address for the from test. A route lookup reports the selected path without sending a packet to the destination. Inspect the output interface, next hop and source address. On hosts with VPNs, containers or multiple uplinks, the default route alone may not explain the application's path. Policy rules and other routing tables can matter.
Inspect application sockets #
Inspect application sockets
Network tools · Local shell; platform and privileges as described below
ss -lntss -lnusudo ss -lntpss -nt state establishedss -nt '( dport = :443 or sport = :443 )'TCP listeners and UDP sockets are separate views. Numeric output makes the port numbers explicit. Process details may need elevated access. Compare the local bind address: 127.0.0.1 is loopback, while a service bound to a network address is a candidate for remote access. A listener still does not prove that the host firewall allows incoming traffic.
Follow the evidence #
If the destination route is unexpected, investigate routing before the application. If the route looks correct but there is no intended listener, investigate the service. If both look correct, compare a local application request with one from an authorized remote client and capture the failing flow.
Remember that namespaces have their own networking state. Commands on the host can show a different view from commands inside a container. Record where each command ran, the selected source address and the observation time. None of the commands above flushes neighbors, changes routes or restarts networking, so the original evidence remains available.
Sources
Documentation reviewed: 8 October 2026