The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show interface addressesip -brief address showView examples
Inspect link countersip -s link show dev eth0View examples
Show routesip route showView examples
Resolve an outbound routeip route get 1.1.1.1View examples
Inspect neighborsip neighbor showView examples
Send a bounded pingping -c 4 example.comView examples
Test IPv6 reachabilityping -6 -c 4 example.comView examples
Show listening TCP socketsss -lntView examples
Show established TCP socketsss -nt state establishedView examples
Include owning processessudo ss -lntpView examples
Use system name resolutiongetent ahosts example.comView examples
Query an A recorddig example.com AView examples
Show concise DNS answersdig +short example.com AAAAView examples
Fetch response headerscurl -I https://example.com/View examples
Print an HTTP statuscurl -sS -o /dev/null -w '%{http_code}\n' \ https://example.com/View examples
Bound connection timecurl --connect-timeout 5 https://example.com/View examples
Trace a requestcurl -v --connect-timeout 5 https://example.com/View examples

Network troubleshooting becomes faster when each check answers one question: does the interface have an address, which route will be used, can the name resolve, can the transport connect, and does the application respond? Record exact targets and timestamps, and avoid treating one successful layer as proof that every later layer works.

Step by step

Detailed examples

01

Confirm local link state and addresses

Begin locally: an interface must be up and have an address suitable for the destination. ip -brief address condenses state and addresses, while ip -s link exposes counters that can reveal dropped or erroring traffic. Interface names vary by system; discover the real name before substituting it into a command.

Compact interface inventory
ip -brief address show
Output
lo               UNKNOWN        127.0.0.1/8 ::1/128
eth0            UP             192.0.2.20/24
Counters for one discovered interface
ip -s link show dev eth0
Output
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP
    RX: bytes  packets  errors  dropped  missed  mcast
        58240   420      0       0        0       0
    TX: bytes  packets  errors  dropped  carrier collsns
        31120   260      0       0        0       0
Back to quick reference ↑
02

Ask the kernel which path it will use

The routing table describes reachable prefixes, but ip route get is often more useful because it resolves one destination using the current policy rules and reports the selected interface, gateway, and source. The neighbor table maps on-link IP addresses to link-layer addresses; FAILED or incomplete entries can indicate a local segment problem rather than an Internet or DNS failure.

Inspect the table and one decision
ip route show
ip route get 1.1.1.1
ip neighbor show
Output
default via 192.0.2.1 dev eth0
192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.20
1.1.1.1 via 192.0.2.1 dev eth0 src 192.0.2.20 uid 1000
192.0.2.1 dev eth0 lladdr 00:11:22:33:44:55 REACHABLE
Back to quick reference ↑
03

Use bounded ICMP tests as one signal

ping measures ICMP echo reachability and round-trip behavior; -c prevents an interactive test from running indefinitely. Loss may reflect congestion, filtering, or the target declining ICMP, so a failed ping does not prove the application is down. Test the same address family the application uses, especially on dual-stack hosts.

Four IPv4 and IPv6 probes
ping -4 -c 4 example.com
ping -6 -c 4 example.com
Output
PING example.com (192.0.2.10) 56(84) bytes of data.
--- example.com ping statistics ---
4 packets transmitted, 4 received, 0% packet loss
PING example.com(2001:db8::10) 56 data bytes
--- example.com ping statistics ---
4 packets transmitted, 4 received, 0% packet loss
Back to quick reference ↑
04

Inspect listeners and live connections with ss

ss reads Linux socket information. Combine -l for listeners, -n for numeric output, -t for TCP, and -p for process details. Process ownership may be hidden without elevated privileges; use sudo only when authorized. A local listener proves a process bound the socket, not that firewalls, routing, or application health permit remote use.

Listeners, owners, and established connections
ss -lnt
sudo ss -lntp
ss -nt state established
Output
State  Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0      4096   127.0.0.1:8080    0.0.0.0:*
State  Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0      4096   127.0.0.1:8080    0.0.0.0:* users:(("app",pid=2400,fd=7))
State Recv-Q Send-Q Local Address:Port Peer Address:Port
ESTAB 0      0      192.0.2.20:44120  198.51.100.8:443
Back to quick reference ↑
05

Separate system resolution from direct DNS queries

getent ahosts follows the system's Name Service Switch configuration, which may include local files and other sources in addition to DNS. dig talks DNS and exposes record types, response codes, and the responding server. Comparing them helps identify resolver-path differences; +short is convenient for data but hides diagnostic context.

Compare configured resolution and DNS records
getent ahosts example.com
dig example.com A
dig +short example.com AAAA
Output
192.0.2.10 STREAM example.com
192.0.2.10 DGRAM
192.0.2.10 RAW
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12345
;; ANSWER SECTION:
example.com. 300 IN A 192.0.2.10
2001:db8::10
Back to quick reference ↑
06

Test the actual application protocol with curl

curl can distinguish name-resolution, connection, TLS, and HTTP behavior. -I requests headers only, while -w reports transfer metadata and -o /dev/null discards a body. A connection timeout bounds only connection establishment; add an overall --max-time when the entire diagnostic must have a deadline.

Inspect headers and capture the status
curl -I --connect-timeout 5 https://example.com/
curl -sS -o /dev/null -w '%{http_code}\n' https://example.com/
Output
HTTP/2 200
content-type: text/html
content-length: 1256

200
Back to quick reference ↑
07

Work outward and preserve evidence

Check the local interface, route decision, name resolution, transport listener or reachability, and application response in order. This narrows the failing boundary and avoids changing unrelated configuration. curl -v is valuable for a final trace, but it can print authorization, cookie, proxy, and certificate details; redact output before sharing it.

A read-only diagnostic sequence
ip -brief address show
ip route get 1.1.1.1
getent ahosts example.com
ss -lnt
curl -v --connect-timeout 5 https://example.com/
Output
# Review each command's output before continuing.
# The verbose curl trace is written to standard error.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux man-pages projectip(8) — show and manipulate routing, devices, and tunnelsman7.org
  2. Linux man-pages projectss(8) — investigate socketsman7.org
  3. Linux man-pages projectping(8) — send ICMP echo requestsman7.org
  4. curl projectcurl command-line manualcurl.se
  5. Internet Systems ConsortiumBIND 9 dig manualbind9.readthedocs.io

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback