Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Linux network troubleshooting is easier when you match the command to the question. Use ip to inspect local addresses and routes, dig or nslookup to check name resolution, nc to test a port, and curl to check an HTTP endpoint. No single successful command proves that the entire network or application is healthy.

Start with the right layer

A useful diagnosis moves from the machine outward: check its interface and route, resolve the destination name, test reachability or a port, then check the application response. If the symptom persists, inspect the path or capture packets. Commands below are conventional shell examples; availability, flags, output, and package names vary by distribution and utility implementation. Install missing tools using your distribution’s package manager. Only probe systems you own or are authorized to test, and use commands that change settings only when you understand the effect.

  1. For local addressing or routing, use ip.
  2. For DNS, use dig or nslookup.
  3. For basic ICMP reachability, use ping.
  4. For a remote TCP port, use nc; for an HTTP response, use curl.
  5. For path details or packet-level evidence, use traceroute, tracepath, or tcpdump.

Check local interfaces, routes, and neighbors

1. ip address: see assigned addresses

Run ip address show (also commonly written ip addr or ip a) to list interfaces and their addresses. Check whether the expected interface is present and has an address appropriate to your network. An address in the output confirms local configuration, not a successful connection to another machine.

2. ip route: see how traffic will be routed

Run ip route show for the IPv4 routing table, or ip -6 route show for IPv6. Look for the route that applies to the destination and the default route when traffic has no more specific match. A route describes the kernel’s selection; it does not prove that packets pass through the gateway or reach the destination.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. ip neigh: inspect local neighbor entries

Run ip neigh show to inspect the kernel’s neighbor table, which helps diagnose address resolution on a directly connected network. These entries are not DNS records: a neighbor table concerns local-link communication, not translation of an Internet hostname into an address.

Check sockets and basic reachability

4. ss: see local sockets

Use ss -tuln to list listening TCP and UDP sockets numerically. Use ss -tan to inspect TCP sockets and their states. This can help establish whether a service is listening locally on the expected port. A local listening socket does not show that a remote firewall, router, or security policy permits access.

5. ping: test ICMP Echo

Run ping -c 4 example.com to send four ICMP Echo requests and stop. Substitute a hostname or address you are permitted to test. A reply shows that Echo traffic received a response along the tested path. No reply is inconclusive: a host, firewall, or network policy may block or suppress ICMP even while an application service works.

Trace a route and investigate path MTU

6. traceroute: view responding hops

Run traceroute -n example.com to probe the path without resolving hop addresses into names. Implementations can offer different probe methods, including UDP, ICMP, or TCP; check the installed command’s help or manual if you need a particular method. Asterisks or missing hops commonly mean probes were filtered or rate-limited, not necessarily that application traffic stops at that point.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. tracepath: trace while checking MTU

Run tracepath example.com to investigate the path and path maximum transmission unit (MTU). Its documented purpose includes path-MTU discovery, and it does not require superuser privileges. Results depend on address family and on information intermediate routers return; treat them as evidence about the probe, not a definitive map of every application packet.

Check whether DNS resolves the name

8. dig: query a record

Try dig example.com A for an IPv4 A-record query or dig example.com AAAA for an IPv6 AAAA-record query. The actual resolver and output depend on the system’s resolver configuration and installed implementation. A DNS answer tells you about name resolution, not whether the returned address accepts connections or serves a working application.

9. nslookup: make a basic lookup

Run nslookup example.com on systems where it is installed. It is a familiar way to make a basic DNS lookup, but options and output vary across implementations. If these two lookup commands disagree, compare which resolver each used and inspect the local resolver configuration before concluding the domain itself is broken.

Test application endpoints and downloads

10. curl: request an HTTP response

Run curl -I https://example.com to request response headers from an HTTP endpoint. curl transfers data to or from a server; it does not interpret the page as a browser would. A returned HTTP status and headers are useful application-layer evidence, but they do not explain every failure in a page’s JavaScript, assets, or user experience. If the endpoint does not support a HEAD request, try a normal request such as curl -v https://example.com/ and inspect the connection and response details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

11. wget: download a known URL

Run wget https://example.com/file to download a specific file non-interactively. GNU Wget is a download utility. Choose an intentional URL and inspect the exit status and output; a successful download checks that particular transfer, not every resource or feature on the site.

Test a remote port or inspect packets

12. nc: attempt a TCP connection

With an OpenBSD-style netcat implementation, nc -vz example.com 443 attempts a TCP connection to port 443 and reports whether it succeeds. The syntax and flags differ among netcat variants, so check nc -h or the local manual if this invocation is rejected. A successful connection establishes transport reachability to that port from this machine; it does not verify TLS, HTTP, or application correctness. Netcat can also listen locally, but listener syntax is implementation-dependent and should be used only for an authorized test.

13. tcpdump: capture matching traffic

On systems supporting the any pseudo-interface, run sudo tcpdump -ni any 'port 53' to observe packets matching port 53 traffic. Root or capture privileges are commonly required. Keep the filter narrow, stop the capture when you have the evidence you need, and handle any saved capture file securely: packet contents can expose sensitive information. tcpdump can also write captures for later analysis; consult its local manual for output-file options.

Inspect Ethernet device settings

14. ethtool: query a wired network device

Run sudo ethtool eth0, replacing eth0 with the actual interface name shown by ip address. It queries driver and hardware settings, particularly for wired Ethernet devices. The tool also has options that control device settings; treat those as advanced administration rather than routine inspection, because they can change system behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Combine results instead of trusting one command

Use a sequence that narrows the failure domain. If ip address shows no expected address, investigate local interface configuration before testing a hostname. If the address exists but no route applies, inspect routing. If a name lookup fails, focus on resolver configuration and DNS. If DNS succeeds but nc cannot reach the relevant port, investigate transport reachability and filtering. If the port connects but curl fails, examine the application protocol, TLS, and server response. If only path probes fail, remember that ICMP and traceroute probes may be filtered while application traffic continues.

These tools answer different questions: ss describes local sockets, nc attempts a remote transport connection, curl makes a URL transfer, and tcpdump observes packets. Choose evidence from the layer where the symptom occurs rather than treating any one result as an all-clear.

Common errors and what to try

  • Command not found: the utility may not be installed or may be named differently in your distribution. Install the appropriate package through that distribution’s package manager, then confirm the available implementation and its help output.
  • ping gets no replies: ICMP Echo may be filtered. Check DNS, the relevant TCP port, or the application endpoint with the corresponding tools rather than assuming the host is down.
  • traceroute shows asterisks: intermediate systems may not respond to probes. Try a supported probe method if appropriate, and compare with an application-layer test; do not infer the exact failure point from silent hops alone.
  • dig and nslookup return different results: implementations or resolver choices may differ. Check which DNS server was queried and repeat with an explicitly chosen resolver only if your network policy allows it.
  • nc -z is rejected: flags vary between netcat versions. Read the installed variant’s usage and use its supported syntax; do not assume an example for one implementation is universal.
  • tcpdump reports permission denied: run it with authorized capture privileges, commonly through sudo, or use the system’s approved packet-capture permissions. Avoid broad captures when a narrow filter is enough.
  • curl -I fails while the site opens in a browser: the endpoint may handle HEAD differently, or the browser may be using behavior not represented by a simple command-line request. Try a normal curl -v request and compare the returned protocol and status.

Or skip the browser setup

For a website screenshot, a network probe can tell you whether an endpoint responds, but it will not produce a rendered screenshot. ScreenshotNeo is a website screenshot API and MCP server: one GET request returns a PNG, JPEG, WebP, or PDF. Its clean-shot flow accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify page verdict and billing status in headers.

For example, using cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Replace the example URL with the page you are authorized to capture and provide your API key. See the ScreenshotNeo API documentation for request options. AI agents can use its MCP server tools, including take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000. Learn about ScreenshotNeo, then sign up free for 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Do these commands work on every Linux distribution?

No. Some tools may need installation, and behavior or options can vary by distribution and implementation. Check the local help or manual for the command actually installed.

Which command should I use to check whether a service is listening on my Linux machine?

Use ss -tuln to inspect local listening sockets, then test remote access separately if that is the issue.

Can a packet capture include sensitive data?

Yes. Limit the capture to the traffic needed for diagnosis, restrict access to capture files, and delete them according to your organization’s handling policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.