How the internet works · Lesson 9 · 35 min

Troubleshooting a network

"The website is down." "I can't connect." "The internet is broken." You'll hear these a lot, and they almost never tell you where the problem is. Good troubleshooters don't guess. They use a method: test one layer at a time, from the bottom up, until they find the first one that fails. This lesson puts everything from this path together into that method.

You will learn

  • The bottom-up ladder, with the command for each rung
  • What each kind of failure points to
  • Checking from both ends, and changing one thing at a time
  • Fixing a real multi-layer outage on Rocky or Ubuntu

The ladder

Climb from the bottom. The first rung that fails is where the problem is, and everything above it is just a symptom.

RungQuestionTryGood answer
1. LinkIs the interface up, with a cable?ip -br link, ethtool enp0s3UP, Link detected: yes
2. AddressDo I have the right address?ip -br addrThe address you expect, not 169.254…
3. Local networkCan I reach my gateway?ping -c 2 192.168.1.1Replies
4. RoutingCan I get beyond it?ip route, ping -c 2 8.8.8.8, tracepath -nA default via line; replies
5. NamesDoes DNS work?getent hosts NAME, dig NAMEAn address
6. PortDoes the service answer?nc -zv HOST PORT, on the server ss -tlnpConnected (not refused, not timed out)
7. ApplicationDoes it answer correctly?curl -v URLThe status code and content you expect

You don't always have to start at the very bottom: one ping to the target tests rungs 1–4 at once. If that works, jump straight to the port. If it fails, go down. That's divide and conquer.

What failures point to

You seeLook at
Network is unreachableNo route: often a missing default gateway (lesson 3)
Destination Host UnreachableNothing answers on the local network: wrong address, or the device is off (lesson 1)
Temporary failure in name resolutionDNS: which server is configured, and can you reach it? (lesson 4)
Timed out on a portA firewall dropping packets, on the server or on the way (lesson 5)
No route to host on a port, while ping worksA firewall that rejects instead of dropping (Rocky's firewalld does this)
Connection refusedThe machine is there, but nothing listens on that port and address: is the service running? Listening on 127.0.0.1 only?
A 4xx/5xx statusThe network is fine: it's the web server or the app (lesson 6)
A certificate errorTLS (lesson 7)

Habits of good troubleshooters

Where the network settings and web server's listening address are kept is Linux-specific:

FixRocky / RHELUbuntu / Debian
Gateway and DNS, for goodsudo nmcli con mod enp0s3 ipv4.gateway … ipv4.dns … then sudo nmcli con up enp0s3routes: and nameservers: in /etc/netplan/*.yaml, then sudo netplan apply
Open the web portsudo firewall-cmd --permanent --add-service=http + --reloadsudo ufw allow 'Apache'
Where Apache listensListen in /etc/httpd/conf/httpd.confListen in /etc/apache2/ports.conf
A path view that keeps updatingsudo dnf install mtr, then mtr 8.8.8.8mtr 8.8.8.8 (mtr-tiny is preinstalled)

Try it: "the website is down" 🧗

You're on your laptop. Nobody can open the club website at http://192.168.1.50, and the server can't download updates either. Climb the ladder, fix each rung, and prove it from both ends.

Quick check

1. curl localhost on the server works, but from the laptop nc -zv 192.168.1.50 80 times out. Where's the problem?

2. After opening the firewall, the laptop gets "connection refused" and ss -tlnp shows 127.0.0.1:80. What's wrong?

3. ping 8.8.8.8 says "Network is unreachable", but ping 192.168.1.1 works. Which rung?

Finished the missions and the quiz? Mark it done to track your progress.