[{"data":1,"prerenderedAt":1978},["ShallowReactive",2],{"page-\u002Flinux\u002F10-networking-fundamentals":3},{"id":4,"title":5,"body":6,"description":1971,"extension":1972,"meta":1973,"navigation":217,"path":1974,"seo":1975,"stem":1976,"__hash__":1977},"content\u002Flinux\u002F10-networking-fundamentals.md","10 — Networking Fundamentals",{"type":7,"value":8,"toc":1945},"minimark",[9,13,37,42,159,163,243,246,300,305,389,393,530,562,566,636,640,747,755,802,812,890,916,922,1046,1050,1166,1175,1278,1282,1390,1394,1437,1441,1555,1559,1656,1660,1786,1790,1793,1807,1817,1941],[10,11,5],"h1",{"id":12},"_10-networking-fundamentals",[14,15,16,17,21,22,25,26,29,30,29,33,36],"p",{},"Networking is how your Linux box talks to other machines — via TCP\u002FIP, DNS, HTTP, SSH. This chapter covers the network stack, interface configuration (",[18,19,20],"code",{},"ip","), routing, DNS, sockets (",[18,23,24],{},"ss","), and the everyday tools (",[18,27,28],{},"curl",", ",[18,31,32],{},"ssh",[18,34,35],{},"rsync",").",[38,39,41],"h2",{"id":40},"the-tcpip-model","The TCP\u002FIP Model",[43,44,46],"code-wrapper",{"language":45},"bash",[47,48,52],"pre",{"className":49,"code":50,"language":45,"meta":51,"style":51},"language-bash shiki shiki-themes github-light github-dark","┌─────────────────────────────────────┐\n│  Application  (HTTP, SSH, DNS, ...)  │  ← your programs\n├─────────────────────────────────────┤\n│  Transport    (TCP \u002F UDP)            │  ← ports, reliability\n├─────────────────────────────────────┤\n│  Internet     (IP)                   │  ← routing, IP addresses\n├─────────────────────────────────────┤\n│  Link         (Ethernet, Wi-Fi)      │  ← MAC addresses, switches\n└─────────────────────────────────────┘\n","",[18,53,54,63,89,95,115,120,131,136,153],{"__ignoreMap":51},[55,56,59],"span",{"class":57,"line":58},"line",1,[55,60,62],{"class":61},"sIsaT","┌─────────────────────────────────────┐\n",[55,64,66,69,73,77,80,83,86],{"class":57,"line":65},2,[55,67,68],{"class":61},"│",[55,70,72],{"class":71},"sJ6F3","  Application",[55,74,76],{"class":75},"ssxIu","  (HTTP, ",[55,78,79],{"class":71},"SSH,",[55,81,82],{"class":71}," DNS,",[55,84,85],{"class":71}," ...",[55,87,88],{"class":75},")  │  ← your programs\n",[55,90,92],{"class":57,"line":91},3,[55,93,94],{"class":61},"├─────────────────────────────────────┤\n",[55,96,98,100,103,106,109,112],{"class":57,"line":97},4,[55,99,68],{"class":61},[55,101,102],{"class":71},"  Transport",[55,104,105],{"class":75},"    (TCP ",[55,107,108],{"class":71},"\u002F",[55,110,111],{"class":71}," UDP",[55,113,114],{"class":75},")            │  ← ports, reliability\n",[55,116,118],{"class":57,"line":117},5,[55,119,94],{"class":61},[55,121,123,125,128],{"class":57,"line":122},6,[55,124,68],{"class":61},[55,126,127],{"class":71},"  Internet",[55,129,130],{"class":75},"     (IP)                   │  ← routing, IP addresses\n",[55,132,134],{"class":57,"line":133},7,[55,135,94],{"class":61},[55,137,139,141,144,147,150],{"class":57,"line":138},8,[55,140,68],{"class":61},[55,142,143],{"class":71},"  Link",[55,145,146],{"class":75},"         (Ethernet, ",[55,148,149],{"class":71},"Wi-Fi",[55,151,152],{"class":75},")      │  ← MAC addresses, switches\n",[55,154,156],{"class":57,"line":155},9,[55,157,158],{"class":61},"└─────────────────────────────────────┘\n",[38,160,162],{"id":161},"network-interfaces","Network Interfaces",[43,164,165],{"language":45},[47,166,168],{"className":49,"code":167,"language":45,"meta":51,"style":51},"# Complex Implementation: comprehensive network state in one command\nip -br addr show              # brief (one line per interface: name, state, IP)\nip route                      # routing table\nss -tlnp                      # TCP listening + process\n\n# Legacy (deprecated but common):\nifconfig                      # interfaces + IPs\nnetstat -rn                   # routing table (use ip route instead)\n",[18,169,170,176,193,203,213,219,224,232],{"__ignoreMap":51},[55,171,172],{"class":57,"line":58},[55,173,175],{"class":174},"sdCPZ","# Complex Implementation: comprehensive network state in one command\n",[55,177,178,180,184,187,190],{"class":57,"line":65},[55,179,20],{"class":61},[55,181,183],{"class":182},"snvgF"," -br",[55,185,186],{"class":71}," addr",[55,188,189],{"class":71}," show",[55,191,192],{"class":174},"              # brief (one line per interface: name, state, IP)\n",[55,194,195,197,200],{"class":57,"line":91},[55,196,20],{"class":61},[55,198,199],{"class":71}," route",[55,201,202],{"class":174},"                      # routing table\n",[55,204,205,207,210],{"class":57,"line":97},[55,206,24],{"class":61},[55,208,209],{"class":182}," -tlnp",[55,211,212],{"class":174},"                      # TCP listening + process\n",[55,214,215],{"class":57,"line":117},[55,216,218],{"emptyLinePlaceholder":217},true,"\n",[55,220,221],{"class":57,"line":122},[55,222,223],{"class":174},"# Legacy (deprecated but common):\n",[55,225,226,229],{"class":57,"line":133},[55,227,228],{"class":61},"ifconfig",[55,230,231],{"class":174},"                      # interfaces + IPs\n",[55,233,234,237,240],{"class":57,"line":138},[55,235,236],{"class":61},"netstat",[55,238,239],{"class":182}," -rn",[55,241,242],{"class":174},"                   # routing table (use ip route instead)\n",[14,244,245],{},"Interface names:",[247,248,249,273,282,291],"ul",{},[250,251,252,29,255,29,258,261,262,265,266,268,269,272],"li",{},[18,253,254],{},"eth0",[18,256,257],{},"enp3s0",[18,259,260],{},"ens33"," — Ethernet (",[18,263,264],{},"en"," = Ethernet, ",[18,267,14],{}," = PCI bus, ",[18,270,271],{},"s"," = slot).",[250,274,275,29,278,281],{},[18,276,277],{},"wlan0",[18,279,280],{},"wlp2s0"," — Wi-Fi.",[250,283,284,287,288,36],{},[18,285,286],{},"lo"," — loopback (",[18,289,290],{},"127.0.0.1",[250,292,293,29,296,299],{},[18,294,295],{},"docker0",[18,297,298],{},"br-xxx"," — Docker bridges.",[301,302,304],"h3",{"id":303},"configuring-temporary","Configuring (Temporary)",[43,306,307],{"language":45},[47,308,310],{"className":49,"code":309,"language":45,"meta":51,"style":51},"sudo ip link set eth0 up               # bring interface up\nsudo ip addr add 192.168.1.10\u002F24 dev eth0   # add an IP\nsudo ip route add default via 192.168.1.1    # default gateway\n# These are TEMPORARY (lost on reboot). Persistent config is in:\n# \u002Fetc\u002Fnetplan\u002F (Ubuntu), \u002Fetc\u002FNetworkManager\u002F or nmcli (RHEL)\n",[18,311,312,335,357,379,384],{"__ignoreMap":51},[55,313,314,317,320,323,326,329,332],{"class":57,"line":58},[55,315,316],{"class":61},"sudo",[55,318,319],{"class":71}," ip",[55,321,322],{"class":71}," link",[55,324,325],{"class":71}," set",[55,327,328],{"class":71}," eth0",[55,330,331],{"class":71}," up",[55,333,334],{"class":174},"               # bring interface up\n",[55,336,337,339,341,343,346,349,352,354],{"class":57,"line":65},[55,338,316],{"class":61},[55,340,319],{"class":71},[55,342,186],{"class":71},[55,344,345],{"class":71}," add",[55,347,348],{"class":71}," 192.168.1.10\u002F24",[55,350,351],{"class":71}," dev",[55,353,328],{"class":71},[55,355,356],{"class":174},"   # add an IP\n",[55,358,359,361,363,365,367,370,373,376],{"class":57,"line":91},[55,360,316],{"class":61},[55,362,319],{"class":71},[55,364,199],{"class":71},[55,366,345],{"class":71},[55,368,369],{"class":71}," default",[55,371,372],{"class":71}," via",[55,374,375],{"class":182}," 192.168.1.1",[55,377,378],{"class":174},"    # default gateway\n",[55,380,381],{"class":57,"line":97},[55,382,383],{"class":174},"# These are TEMPORARY (lost on reboot). Persistent config is in:\n",[55,385,386],{"class":57,"line":117},[55,387,388],{"class":174},"# \u002Fetc\u002Fnetplan\u002F (Ubuntu), \u002Fetc\u002FNetworkManager\u002F or nmcli (RHEL)\n",[301,390,392],{"id":391},"ubuntu-netplan","Ubuntu — Netplan",[43,394,396],{"language":395},"yaml",[47,397,400],{"className":398,"code":399,"language":395,"meta":51,"style":51},"language-yaml shiki shiki-themes github-light github-dark","# \u002Fetc\u002Fnetplan\u002F01-netcfg.yaml\nnetwork:\n  version: 2\n  ethernets:\n    eth0:\n      dhcp4: true\n    eth1:\n      addresses: [192.168.1.10\u002F24]\n      routes:\n        - to: default\n          via: 192.168.1.1\n      nameservers:\n        addresses: [8.8.8.8, 1.1.1.1]\n",[18,401,402,407,416,427,434,441,451,458,472,479,493,504,512],{"__ignoreMap":51},[55,403,404],{"class":57,"line":58},[55,405,406],{"class":174},"# \u002Fetc\u002Fnetplan\u002F01-netcfg.yaml\n",[55,408,409,413],{"class":57,"line":65},[55,410,412],{"class":411},"sk71V","network",[55,414,415],{"class":75},":\n",[55,417,418,421,424],{"class":57,"line":91},[55,419,420],{"class":411},"  version",[55,422,423],{"class":75},": ",[55,425,426],{"class":182},"2\n",[55,428,429,432],{"class":57,"line":97},[55,430,431],{"class":411},"  ethernets",[55,433,415],{"class":75},[55,435,436,439],{"class":57,"line":117},[55,437,438],{"class":411},"    eth0",[55,440,415],{"class":75},[55,442,443,446,448],{"class":57,"line":122},[55,444,445],{"class":411},"      dhcp4",[55,447,423],{"class":75},[55,449,450],{"class":182},"true\n",[55,452,453,456],{"class":57,"line":133},[55,454,455],{"class":411},"    eth1",[55,457,415],{"class":75},[55,459,460,463,466,469],{"class":57,"line":138},[55,461,462],{"class":411},"      addresses",[55,464,465],{"class":75},": [",[55,467,468],{"class":71},"192.168.1.10\u002F24",[55,470,471],{"class":75},"]\n",[55,473,474,477],{"class":57,"line":155},[55,475,476],{"class":411},"      routes",[55,478,415],{"class":75},[55,480,482,485,488,490],{"class":57,"line":481},10,[55,483,484],{"class":75},"        - ",[55,486,487],{"class":411},"to",[55,489,423],{"class":75},[55,491,492],{"class":71},"default\n",[55,494,496,499,501],{"class":57,"line":495},11,[55,497,498],{"class":411},"          via",[55,500,423],{"class":75},[55,502,503],{"class":182},"192.168.1.1\n",[55,505,507,510],{"class":57,"line":506},12,[55,508,509],{"class":411},"      nameservers",[55,511,415],{"class":75},[55,513,515,518,520,523,525,528],{"class":57,"line":514},13,[55,516,517],{"class":411},"        addresses",[55,519,465],{"class":75},[55,521,522],{"class":182},"8.8.8.8",[55,524,29],{"class":75},[55,526,527],{"class":182},"1.1.1.1",[55,529,471],{"class":75},[43,531,532],{"language":45},[47,533,535],{"className":49,"code":534,"language":45,"meta":51,"style":51},"sudo netplan apply          # apply config\nsudo netplan try            # test (rolls back if you don't confirm in 120s)\n",[18,536,537,550],{"__ignoreMap":51},[55,538,539,541,544,547],{"class":57,"line":58},[55,540,316],{"class":61},[55,542,543],{"class":71}," netplan",[55,545,546],{"class":71}," apply",[55,548,549],{"class":174},"          # apply config\n",[55,551,552,554,556,559],{"class":57,"line":65},[55,553,316],{"class":61},[55,555,543],{"class":71},[55,557,558],{"class":71}," try",[55,560,561],{"class":174},"            # test (rolls back if you don't confirm in 120s)\n",[38,563,565],{"id":564},"routing","Routing",[43,567,568],{"language":45},[47,569,571],{"className":49,"code":570,"language":45,"meta":51,"style":51},"# Complex Implementation: diagnose \"can't reach X\"\nip route                      # show routing table\nip route get 8.8.8.8          # which route + interface for this destination?\ntracepath 8.8.8.8             # trace the path (no root needed)\nmtr 8.8.8.8                   # continuous traceroute (live)\n\n# default route — where packets go if no other route matches (your gateway)\n# 192.168.1.0\u002F24 dev eth0 — this subnet is directly on eth0 (no router)\n",[18,572,573,578,587,602,612,622,626,631],{"__ignoreMap":51},[55,574,575],{"class":57,"line":58},[55,576,577],{"class":174},"# Complex Implementation: diagnose \"can't reach X\"\n",[55,579,580,582,584],{"class":57,"line":65},[55,581,20],{"class":61},[55,583,199],{"class":71},[55,585,586],{"class":174},"                      # show routing table\n",[55,588,589,591,593,596,599],{"class":57,"line":91},[55,590,20],{"class":61},[55,592,199],{"class":71},[55,594,595],{"class":71}," get",[55,597,598],{"class":182}," 8.8.8.8",[55,600,601],{"class":174},"          # which route + interface for this destination?\n",[55,603,604,607,609],{"class":57,"line":97},[55,605,606],{"class":61},"tracepath",[55,608,598],{"class":182},[55,610,611],{"class":174},"             # trace the path (no root needed)\n",[55,613,614,617,619],{"class":57,"line":117},[55,615,616],{"class":61},"mtr",[55,618,598],{"class":182},[55,620,621],{"class":174},"                   # continuous traceroute (live)\n",[55,623,624],{"class":57,"line":122},[55,625,218],{"emptyLinePlaceholder":217},[55,627,628],{"class":57,"line":133},[55,629,630],{"class":174},"# default route — where packets go if no other route matches (your gateway)\n",[55,632,633],{"class":57,"line":138},[55,634,635],{"class":174},"# 192.168.1.0\u002F24 dev eth0 — this subnet is directly on eth0 (no router)\n",[38,637,639],{"id":638},"dns","DNS",[43,641,642],{"language":45},[47,643,645],{"className":49,"code":644,"language":45,"meta":51,"style":51},"# Complex Implementation: full DNS diagnostic chain\ncat \u002Fetc\u002Fresolv.conf                # nameservers (often auto-generated)\ncat \u002Fetc\u002Fhosts                      # static overrides (checked BEFORE DNS)\ncat \u002Fetc\u002Fnsswitch.conf | grep hosts # order: files dns?\ndig example.com                     # full DNS query (A record)\ndig @8.8.8.8 example.com            # query a specific server\ngetent hosts example.com            # via NSS (checks \u002Fetc\u002Fhosts, then DNS)\n\n# Edge Case: \u002Fetc\u002Fhosts overrides DNS\n# If \u002Fetc\u002Fhosts has \"127.0.0.1 example.com\", dig shows the real IP\n# but getent\u002Fcurl\u002Fping use 127.0.0.1 (hosts is checked first)\n",[18,646,647,652,663,673,693,704,716,728,732,737,742],{"__ignoreMap":51},[55,648,649],{"class":57,"line":58},[55,650,651],{"class":174},"# Complex Implementation: full DNS diagnostic chain\n",[55,653,654,657,660],{"class":57,"line":65},[55,655,656],{"class":61},"cat",[55,658,659],{"class":71}," \u002Fetc\u002Fresolv.conf",[55,661,662],{"class":174},"                # nameservers (often auto-generated)\n",[55,664,665,667,670],{"class":57,"line":91},[55,666,656],{"class":61},[55,668,669],{"class":71}," \u002Fetc\u002Fhosts",[55,671,672],{"class":174},"                      # static overrides (checked BEFORE DNS)\n",[55,674,675,677,680,684,687,690],{"class":57,"line":97},[55,676,656],{"class":61},[55,678,679],{"class":71}," \u002Fetc\u002Fnsswitch.conf",[55,681,683],{"class":682},"svdQ7"," |",[55,685,686],{"class":61}," grep",[55,688,689],{"class":71}," hosts",[55,691,692],{"class":174}," # order: files dns?\n",[55,694,695,698,701],{"class":57,"line":117},[55,696,697],{"class":61},"dig",[55,699,700],{"class":71}," example.com",[55,702,703],{"class":174},"                     # full DNS query (A record)\n",[55,705,706,708,711,713],{"class":57,"line":122},[55,707,697],{"class":61},[55,709,710],{"class":71}," @8.8.8.8",[55,712,700],{"class":71},[55,714,715],{"class":174},"            # query a specific server\n",[55,717,718,721,723,725],{"class":57,"line":133},[55,719,720],{"class":61},"getent",[55,722,689],{"class":71},[55,724,700],{"class":71},[55,726,727],{"class":174},"            # via NSS (checks \u002Fetc\u002Fhosts, then DNS)\n",[55,729,730],{"class":57,"line":138},[55,731,218],{"emptyLinePlaceholder":217},[55,733,734],{"class":57,"line":155},[55,735,736],{"class":174},"# Edge Case: \u002Fetc\u002Fhosts overrides DNS\n",[55,738,739],{"class":57,"line":481},[55,740,741],{"class":174},"# If \u002Fetc\u002Fhosts has \"127.0.0.1 example.com\", dig shows the real IP\n",[55,743,744],{"class":57,"line":495},[55,745,746],{"class":174},"# but getent\u002Fcurl\u002Fping use 127.0.0.1 (hosts is checked first)\n",[301,748,750,751,754],{"id":749},"edge-case-resolvconf-is-often-auto-generated","Edge Case: ",[18,752,753],{},"resolv.conf"," Is Often Auto-Generated",[43,756,757],{"language":45},[47,758,760],{"className":49,"code":759,"language":45,"meta":51,"style":51},"# On modern systems, resolv.conf is generated by systemd-resolved or NetworkManager\n# Don't edit it directly — changes are overwritten\nresolvectl status                   # systemd-resolved status\nresolvectl dns eth0 8.8.8.8         # set DNS for an interface\n# Edit Netplan\u002FNetworkManager config for persistence\n",[18,761,762,767,772,783,797],{"__ignoreMap":51},[55,763,764],{"class":57,"line":58},[55,765,766],{"class":174},"# On modern systems, resolv.conf is generated by systemd-resolved or NetworkManager\n",[55,768,769],{"class":57,"line":65},[55,770,771],{"class":174},"# Don't edit it directly — changes are overwritten\n",[55,773,774,777,780],{"class":57,"line":91},[55,775,776],{"class":61},"resolvectl",[55,778,779],{"class":71}," status",[55,781,782],{"class":174},"                   # systemd-resolved status\n",[55,784,785,787,790,792,794],{"class":57,"line":97},[55,786,776],{"class":61},[55,788,789],{"class":71}," dns",[55,791,328],{"class":71},[55,793,598],{"class":182},[55,795,796],{"class":174},"         # set DNS for an interface\n",[55,798,799],{"class":57,"line":117},[55,800,801],{"class":174},"# Edit Netplan\u002FNetworkManager config for persistence\n",[38,803,805,806,808,809,811],{"id":804},"sockets-ss-replaces-netstat","Sockets — ",[18,807,24],{}," (Replaces ",[18,810,236],{},")",[43,813,814],{"language":45},[47,815,817],{"className":49,"code":816,"language":45,"meta":51,"style":51},"# Complex Implementation: find what's listening on port 80 + established connections\nss -tlnp | grep :80              # TCP listening + numeric + process\nss -t state established          # all established TCP connections\nss -t state time-wait            # connections in TIME_WAIT\nss -s                            # socket summary\nss -i                            # internal TCP info (RTT, congestion, cwnd)\n",[18,818,819,824,840,856,870,880],{"__ignoreMap":51},[55,820,821],{"class":57,"line":58},[55,822,823],{"class":174},"# Complex Implementation: find what's listening on port 80 + established connections\n",[55,825,826,828,830,832,834,837],{"class":57,"line":65},[55,827,24],{"class":61},[55,829,209],{"class":182},[55,831,683],{"class":682},[55,833,686],{"class":61},[55,835,836],{"class":71}," :80",[55,838,839],{"class":174},"              # TCP listening + numeric + process\n",[55,841,842,844,847,850,853],{"class":57,"line":91},[55,843,24],{"class":61},[55,845,846],{"class":182}," -t",[55,848,849],{"class":71}," state",[55,851,852],{"class":71}," established",[55,854,855],{"class":174},"          # all established TCP connections\n",[55,857,858,860,862,864,867],{"class":57,"line":97},[55,859,24],{"class":61},[55,861,846],{"class":182},[55,863,849],{"class":71},[55,865,866],{"class":71}," time-wait",[55,868,869],{"class":174},"            # connections in TIME_WAIT\n",[55,871,872,874,877],{"class":57,"line":117},[55,873,24],{"class":61},[55,875,876],{"class":182}," -s",[55,878,879],{"class":174},"                            # socket summary\n",[55,881,882,884,887],{"class":57,"line":122},[55,883,24],{"class":61},[55,885,886],{"class":182}," -i",[55,888,889],{"class":174},"                            # internal TCP info (RTT, congestion, cwnd)\n",[14,891,892,893,895,896,899,900,903,904,907,908,911,912,915],{},"Common ",[18,894,24],{}," flags: ",[18,897,898],{},"-t"," TCP, ",[18,901,902],{},"-u"," UDP, ",[18,905,906],{},"-l"," listening, ",[18,909,910],{},"-n"," numeric (don't resolve), ",[18,913,914],{},"-p"," show process.",[38,917,919,920],{"id":918},"http-curl","HTTP — ",[18,921,28],{},[43,923,924],{"language":45},[47,925,927],{"className":49,"code":926,"language":45,"meta":51,"style":51},"# Complex Implementation: production HTTP health check\ncurl -s -o \u002Fdev\u002Fnull -w \"%{http_code} %{time_total}s\\n\" https:\u002F\u002Fexample.com\n# 200 0.342s\n\n# POST JSON with headers:\ncurl -H \"Content-Type: application\u002Fjson\" \\\n     -d '{\"key\":\"value\"}' \\\n     https:\u002F\u002Fapi.example.com\n\n# Override DNS (test a specific server without changing DNS):\ncurl --resolve example.com:443:1.2.3.4 https:\u002F\u002Fexample.com\n\n# Debug TLS:\ncurl -v https:\u002F\u002Fexample.com 2>&1 | head\n",[18,928,929,934,955,960,964,969,982,992,997,1001,1006,1018,1022,1027],{"__ignoreMap":51},[55,930,931],{"class":57,"line":58},[55,932,933],{"class":174},"# Complex Implementation: production HTTP health check\n",[55,935,936,938,940,943,946,949,952],{"class":57,"line":65},[55,937,28],{"class":61},[55,939,876],{"class":182},[55,941,942],{"class":182}," -o",[55,944,945],{"class":71}," \u002Fdev\u002Fnull",[55,947,948],{"class":182}," -w",[55,950,951],{"class":71}," \"%{http_code} %{time_total}s\\n\"",[55,953,954],{"class":71}," https:\u002F\u002Fexample.com\n",[55,956,957],{"class":57,"line":91},[55,958,959],{"class":174},"# 200 0.342s\n",[55,961,962],{"class":57,"line":97},[55,963,218],{"emptyLinePlaceholder":217},[55,965,966],{"class":57,"line":117},[55,967,968],{"class":174},"# POST JSON with headers:\n",[55,970,971,973,976,979],{"class":57,"line":122},[55,972,28],{"class":61},[55,974,975],{"class":182}," -H",[55,977,978],{"class":71}," \"Content-Type: application\u002Fjson\"",[55,980,981],{"class":182}," \\\n",[55,983,984,987,990],{"class":57,"line":133},[55,985,986],{"class":182},"     -d",[55,988,989],{"class":71}," '{\"key\":\"value\"}'",[55,991,981],{"class":182},[55,993,994],{"class":57,"line":138},[55,995,996],{"class":71},"     https:\u002F\u002Fapi.example.com\n",[55,998,999],{"class":57,"line":155},[55,1000,218],{"emptyLinePlaceholder":217},[55,1002,1003],{"class":57,"line":481},[55,1004,1005],{"class":174},"# Override DNS (test a specific server without changing DNS):\n",[55,1007,1008,1010,1013,1016],{"class":57,"line":495},[55,1009,28],{"class":61},[55,1011,1012],{"class":182}," --resolve",[55,1014,1015],{"class":71}," example.com:443:1.2.3.4",[55,1017,954],{"class":71},[55,1019,1020],{"class":57,"line":506},[55,1021,218],{"emptyLinePlaceholder":217},[55,1023,1024],{"class":57,"line":514},[55,1025,1026],{"class":174},"# Debug TLS:\n",[55,1028,1030,1032,1035,1038,1041,1043],{"class":57,"line":1029},14,[55,1031,28],{"class":61},[55,1033,1034],{"class":182}," -v",[55,1036,1037],{"class":71}," https:\u002F\u002Fexample.com",[55,1039,1040],{"class":682}," 2>&1",[55,1042,683],{"class":682},[55,1044,1045],{"class":61}," head\n",[38,1047,1049],{"id":1048},"ssh-secure-shell","SSH — Secure Shell",[43,1051,1052],{"language":45},[47,1053,1055],{"className":49,"code":1054,"language":45,"meta":51,"style":51},"# Complex Implementation: jump host (bastion) to reach an internal server\nssh -J jumpuser@jumphost alice@internal.server\n\n# Local port forward (tunnel to an internal service):\nssh -L 8080:internal-app:80 alice@bastion\n# Now localhost:8080 → internal-app:80 (via bastion)\n\n# Dynamic SOCKS proxy:\nssh -D 1080 alice@server\n\n# SSH config file simplifies frequent connections:\n# ~\u002F.ssh\u002Fconfig\n# Host prod\n#     HostName prod.example.com\n#     User alice\n#     Port 2222\n#     IdentityFile ~\u002F.ssh\u002Fid_ed25519\n",[18,1056,1057,1062,1075,1079,1084,1097,1102,1106,1111,1124,1128,1133,1138,1143,1148,1154,1160],{"__ignoreMap":51},[55,1058,1059],{"class":57,"line":58},[55,1060,1061],{"class":174},"# Complex Implementation: jump host (bastion) to reach an internal server\n",[55,1063,1064,1066,1069,1072],{"class":57,"line":65},[55,1065,32],{"class":61},[55,1067,1068],{"class":182}," -J",[55,1070,1071],{"class":71}," jumpuser@jumphost",[55,1073,1074],{"class":71}," alice@internal.server\n",[55,1076,1077],{"class":57,"line":91},[55,1078,218],{"emptyLinePlaceholder":217},[55,1080,1081],{"class":57,"line":97},[55,1082,1083],{"class":174},"# Local port forward (tunnel to an internal service):\n",[55,1085,1086,1088,1091,1094],{"class":57,"line":117},[55,1087,32],{"class":61},[55,1089,1090],{"class":182}," -L",[55,1092,1093],{"class":71}," 8080:internal-app:80",[55,1095,1096],{"class":71}," alice@bastion\n",[55,1098,1099],{"class":57,"line":122},[55,1100,1101],{"class":174},"# Now localhost:8080 → internal-app:80 (via bastion)\n",[55,1103,1104],{"class":57,"line":133},[55,1105,218],{"emptyLinePlaceholder":217},[55,1107,1108],{"class":57,"line":138},[55,1109,1110],{"class":174},"# Dynamic SOCKS proxy:\n",[55,1112,1113,1115,1118,1121],{"class":57,"line":155},[55,1114,32],{"class":61},[55,1116,1117],{"class":182}," -D",[55,1119,1120],{"class":182}," 1080",[55,1122,1123],{"class":71}," alice@server\n",[55,1125,1126],{"class":57,"line":481},[55,1127,218],{"emptyLinePlaceholder":217},[55,1129,1130],{"class":57,"line":495},[55,1131,1132],{"class":174},"# SSH config file simplifies frequent connections:\n",[55,1134,1135],{"class":57,"line":506},[55,1136,1137],{"class":174},"# ~\u002F.ssh\u002Fconfig\n",[55,1139,1140],{"class":57,"line":514},[55,1141,1142],{"class":174},"# Host prod\n",[55,1144,1145],{"class":57,"line":1029},[55,1146,1147],{"class":174},"#     HostName prod.example.com\n",[55,1149,1151],{"class":57,"line":1150},15,[55,1152,1153],{"class":174},"#     User alice\n",[55,1155,1157],{"class":57,"line":1156},16,[55,1158,1159],{"class":174},"#     Port 2222\n",[55,1161,1163],{"class":57,"line":1162},17,[55,1164,1165],{"class":174},"#     IdentityFile ~\u002F.ssh\u002Fid_ed25519\n",[38,1167,1169,1171,1172,811],{"id":1168},"rsync-preferred-over-scp",[18,1170,35],{}," (Preferred over ",[18,1173,1174],{},"scp",[43,1176,1177],{"language":45},[47,1178,1180],{"className":49,"code":1179,"language":45,"meta":51,"style":51},"# Complex Implementation: efficient sync with delete + exclude + dry-run\nrsync -avz --delete --exclude='*.log' --exclude='node_modules' dir\u002F alice@server:\u002Ftmp\u002Fdir\u002F\n# -a: archive (recursive, preserve perms\u002Fowner\u002Ftimestamps)\n# -v: verbose\n# -z: compress\n# --delete: delete files on dest not in source\n# --exclude: skip patterns\n\n# Trailing slash matters:\n# rsync dir\u002F dest\u002F  → copies CONTENTS of dir into dest (dest\u002Ffile1)\n# rsync dir dest\u002F   → copies dir itself into dest (dest\u002Fdir\u002Ffile1)\n\n# Always dry-run first:\nrsync -avzn dir\u002F alice@server:\u002Ftmp\u002Fdir\u002F\n",[18,1181,1182,1187,1214,1219,1224,1229,1234,1239,1243,1248,1253,1258,1262,1267],{"__ignoreMap":51},[55,1183,1184],{"class":57,"line":58},[55,1185,1186],{"class":174},"# Complex Implementation: efficient sync with delete + exclude + dry-run\n",[55,1188,1189,1191,1194,1197,1200,1203,1205,1208,1211],{"class":57,"line":65},[55,1190,35],{"class":61},[55,1192,1193],{"class":182}," -avz",[55,1195,1196],{"class":182}," --delete",[55,1198,1199],{"class":182}," --exclude=",[55,1201,1202],{"class":71},"'*.log'",[55,1204,1199],{"class":182},[55,1206,1207],{"class":71},"'node_modules'",[55,1209,1210],{"class":71}," dir\u002F",[55,1212,1213],{"class":71}," alice@server:\u002Ftmp\u002Fdir\u002F\n",[55,1215,1216],{"class":57,"line":91},[55,1217,1218],{"class":174},"# -a: archive (recursive, preserve perms\u002Fowner\u002Ftimestamps)\n",[55,1220,1221],{"class":57,"line":97},[55,1222,1223],{"class":174},"# -v: verbose\n",[55,1225,1226],{"class":57,"line":117},[55,1227,1228],{"class":174},"# -z: compress\n",[55,1230,1231],{"class":57,"line":122},[55,1232,1233],{"class":174},"# --delete: delete files on dest not in source\n",[55,1235,1236],{"class":57,"line":133},[55,1237,1238],{"class":174},"# --exclude: skip patterns\n",[55,1240,1241],{"class":57,"line":138},[55,1242,218],{"emptyLinePlaceholder":217},[55,1244,1245],{"class":57,"line":155},[55,1246,1247],{"class":174},"# Trailing slash matters:\n",[55,1249,1250],{"class":57,"line":481},[55,1251,1252],{"class":174},"# rsync dir\u002F dest\u002F  → copies CONTENTS of dir into dest (dest\u002Ffile1)\n",[55,1254,1255],{"class":57,"line":495},[55,1256,1257],{"class":174},"# rsync dir dest\u002F   → copies dir itself into dest (dest\u002Fdir\u002Ffile1)\n",[55,1259,1260],{"class":57,"line":506},[55,1261,218],{"emptyLinePlaceholder":217},[55,1263,1264],{"class":57,"line":514},[55,1265,1266],{"class":174},"# Always dry-run first:\n",[55,1268,1269,1271,1274,1276],{"class":57,"line":1029},[55,1270,35],{"class":61},[55,1272,1273],{"class":182}," -avzn",[55,1275,1210],{"class":71},[55,1277,1213],{"class":71},[38,1279,1281],{"id":1280},"firewall","Firewall",[43,1283,1284],{"language":45},[47,1285,1287],{"className":49,"code":1286,"language":45,"meta":51,"style":51},"# UFW (Ubuntu)\nsudo ufw allow 22\u002Ftcp\nsudo ufw allow 80\u002Ftcp\nsudo ufw allow 443\u002Ftcp\nsudo ufw limit 22\u002Ftcp           # rate-limit SSH (blocks brute force)\nsudo ufw --force enable\n\n# firewalld (RHEL)\nsudo firewall-cmd --zone=public --add-service=http --permanent\nsudo firewall-cmd --reload\n",[18,1288,1289,1294,1307,1318,1329,1344,1356,1360,1365,1381],{"__ignoreMap":51},[55,1290,1291],{"class":57,"line":58},[55,1292,1293],{"class":174},"# UFW (Ubuntu)\n",[55,1295,1296,1298,1301,1304],{"class":57,"line":65},[55,1297,316],{"class":61},[55,1299,1300],{"class":71}," ufw",[55,1302,1303],{"class":71}," allow",[55,1305,1306],{"class":71}," 22\u002Ftcp\n",[55,1308,1309,1311,1313,1315],{"class":57,"line":91},[55,1310,316],{"class":61},[55,1312,1300],{"class":71},[55,1314,1303],{"class":71},[55,1316,1317],{"class":71}," 80\u002Ftcp\n",[55,1319,1320,1322,1324,1326],{"class":57,"line":97},[55,1321,316],{"class":61},[55,1323,1300],{"class":71},[55,1325,1303],{"class":71},[55,1327,1328],{"class":71}," 443\u002Ftcp\n",[55,1330,1331,1333,1335,1338,1341],{"class":57,"line":117},[55,1332,316],{"class":61},[55,1334,1300],{"class":71},[55,1336,1337],{"class":71}," limit",[55,1339,1340],{"class":71}," 22\u002Ftcp",[55,1342,1343],{"class":174},"           # rate-limit SSH (blocks brute force)\n",[55,1345,1346,1348,1350,1353],{"class":57,"line":122},[55,1347,316],{"class":61},[55,1349,1300],{"class":71},[55,1351,1352],{"class":182}," --force",[55,1354,1355],{"class":71}," enable\n",[55,1357,1358],{"class":57,"line":133},[55,1359,218],{"emptyLinePlaceholder":217},[55,1361,1362],{"class":57,"line":138},[55,1363,1364],{"class":174},"# firewalld (RHEL)\n",[55,1366,1367,1369,1372,1375,1378],{"class":57,"line":155},[55,1368,316],{"class":61},[55,1370,1371],{"class":71}," firewall-cmd",[55,1373,1374],{"class":182}," --zone=public",[55,1376,1377],{"class":182}," --add-service=http",[55,1379,1380],{"class":182}," --permanent\n",[55,1382,1383,1385,1387],{"class":57,"line":481},[55,1384,316],{"class":61},[55,1386,1371],{"class":71},[55,1388,1389],{"class":182}," --reload\n",[301,1391,1393],{"id":1392},"caveat-always-allow-ssh-before-enabling-ufw","Caveat: Always Allow SSH Before Enabling UFW",[43,1395,1396],{"language":45},[47,1397,1399],{"className":49,"code":1398,"language":45,"meta":51,"style":51},"# NAIVE: enable firewall without allowing SSH → locked out\nsudo ufw enable\n# PRODUCTION: allow SSH first\nsudo ufw allow 22\u002Ftcp\nsudo ufw enable\n",[18,1400,1401,1406,1414,1419,1429],{"__ignoreMap":51},[55,1402,1403],{"class":57,"line":58},[55,1404,1405],{"class":174},"# NAIVE: enable firewall without allowing SSH → locked out\n",[55,1407,1408,1410,1412],{"class":57,"line":65},[55,1409,316],{"class":61},[55,1411,1300],{"class":71},[55,1413,1355],{"class":71},[55,1415,1416],{"class":57,"line":91},[55,1417,1418],{"class":174},"# PRODUCTION: allow SSH first\n",[55,1420,1421,1423,1425,1427],{"class":57,"line":97},[55,1422,316],{"class":61},[55,1424,1300],{"class":71},[55,1426,1303],{"class":71},[55,1428,1306],{"class":71},[55,1430,1431,1433,1435],{"class":57,"line":117},[55,1432,316],{"class":61},[55,1434,1300],{"class":71},[55,1436,1355],{"class":71},[38,1438,1440],{"id":1439},"diagnostics","Diagnostics",[43,1442,1443],{"language":45},[47,1444,1446],{"className":49,"code":1445,"language":45,"meta":51,"style":51},"# Complex Implementation: network diagnostic flow\nping -c 4 8.8.8.8               # is the host reachable? (ICMP)\nmtr 8.8.8.8                     # where does it fail? (continuous traceroute)\nnc -zv example.com 80           # is port 80 open?\nsudo tcpdump -i eth0 port 80 -n # capture port 80 traffic\ndig example.com                 # DNS resolving?\ncurl -v https:\u002F\u002Fexample.com    # HTTP working?\n\n# Edge Case: ping fails but host is up\n# Some firewalls block ICMP. A failed ping doesn't always mean the host is down.\n# Try curl or nc instead.\n",[18,1447,1448,1453,1469,1478,1494,1516,1525,1536,1540,1545,1550],{"__ignoreMap":51},[55,1449,1450],{"class":57,"line":58},[55,1451,1452],{"class":174},"# Complex Implementation: network diagnostic flow\n",[55,1454,1455,1458,1461,1464,1466],{"class":57,"line":65},[55,1456,1457],{"class":61},"ping",[55,1459,1460],{"class":182}," -c",[55,1462,1463],{"class":182}," 4",[55,1465,598],{"class":182},[55,1467,1468],{"class":174},"               # is the host reachable? (ICMP)\n",[55,1470,1471,1473,1475],{"class":57,"line":91},[55,1472,616],{"class":61},[55,1474,598],{"class":182},[55,1476,1477],{"class":174},"                     # where does it fail? (continuous traceroute)\n",[55,1479,1480,1483,1486,1488,1491],{"class":57,"line":97},[55,1481,1482],{"class":61},"nc",[55,1484,1485],{"class":182}," -zv",[55,1487,700],{"class":71},[55,1489,1490],{"class":182}," 80",[55,1492,1493],{"class":174},"           # is port 80 open?\n",[55,1495,1496,1498,1501,1503,1505,1508,1510,1513],{"class":57,"line":117},[55,1497,316],{"class":61},[55,1499,1500],{"class":71}," tcpdump",[55,1502,886],{"class":182},[55,1504,328],{"class":71},[55,1506,1507],{"class":71}," port",[55,1509,1490],{"class":182},[55,1511,1512],{"class":182}," -n",[55,1514,1515],{"class":174}," # capture port 80 traffic\n",[55,1517,1518,1520,1522],{"class":57,"line":122},[55,1519,697],{"class":61},[55,1521,700],{"class":71},[55,1523,1524],{"class":174},"                 # DNS resolving?\n",[55,1526,1527,1529,1531,1533],{"class":57,"line":133},[55,1528,28],{"class":61},[55,1530,1034],{"class":182},[55,1532,1037],{"class":71},[55,1534,1535],{"class":174},"    # HTTP working?\n",[55,1537,1538],{"class":57,"line":138},[55,1539,218],{"emptyLinePlaceholder":217},[55,1541,1542],{"class":57,"line":155},[55,1543,1544],{"class":174},"# Edge Case: ping fails but host is up\n",[55,1546,1547],{"class":57,"line":481},[55,1548,1549],{"class":174},"# Some firewalls block ICMP. A failed ping doesn't always mean the host is down.\n",[55,1551,1552],{"class":57,"line":495},[55,1553,1554],{"class":174},"# Try curl or nc instead.\n",[38,1556,1558],{"id":1557},"tips-tricks","💡 Tips & Tricks",[247,1560,1561,1584,1600,1615,1623,1639],{},[250,1562,1563,1567,1568,1570,1571,1573,1574,1576,1577,1579,1580,1583],{},[1564,1565,1566],"strong",{},"Idiom",": use ",[18,1569,24],{}," (not ",[18,1572,236],{},") for socket statistics — ",[18,1575,24],{}," is faster, more informative, and ",[18,1578,236],{}," is deprecated. ",[18,1581,1582],{},"ss -tlnp"," is the go-to for \"what's listening?\"",[250,1585,1586,1567,1588,1570,1590,1592,1593,1595,1596,1599],{},[1564,1587,1566],{},[18,1589,20],{},[18,1591,228],{},") for interface config — ",[18,1594,228],{}," is deprecated and missing features. ",[18,1597,1598],{},"ip -br addr"," gives a clean one-line-per-interface view.",[250,1601,1602,1567,1604,1570,1606,1608,1609,1611,1612,1614],{},[1564,1603,1566],{},[18,1605,35],{},[18,1607,1174],{},") for file transfer — ",[18,1610,35],{}," only sends diffs, resumes interrupted transfers, and preserves attributes. ",[18,1613,1174],{}," copies the whole file every time.",[250,1616,1617,1567,1619,1622],{},[1564,1618,1566],{},[18,1620,1621],{},"curl -s -o \u002Fdev\u002Fnull -w \"%{http_code}\""," for script-friendly HTTP checks — extracts just the status code, no body.",[250,1624,1625,1567,1627,1630,1631,1634,1635,1638],{},[1564,1626,1566],{},[18,1628,1629],{},"dig +short"," for just the IP — ",[18,1632,1633],{},"dig +short example.com"," gives ",[18,1636,1637],{},"93.184.216.34"," (no headers, no metadata).",[250,1640,1641,1567,1644,1570,1646,1649,1650,1652,1653,1655],{},[1564,1642,1643],{},"Debug",[18,1645,616],{},[18,1647,1648],{},"traceroute",") for live route diagnosis — ",[18,1651,616],{}," updates continuously, showing packet loss per hop. ",[18,1654,1648],{}," is one-shot.",[38,1657,1659],{"id":1658},"️-edge-cases-gotchas","⚠️ Edge Cases & Gotchas",[247,1661,1662,1668,1699,1714,1732,1761,1772],{},[250,1663,1664,1667],{},[1564,1665,1666],{},"\"Connection refused\" vs \"Connection timed out\"",": refused = something is listening but refused you (port closed, or firewall REJECT). Timed out = nothing responded (firewall DROP, or network issue). The distinction matters for diagnosis.",[250,1669,1670,423,1676,1678,1679,423,1682,1685,1686,1688,1689,1691,1692,1694,1695,1698],{},[1564,1671,1672,1675],{},[18,1673,1674],{},"\u002Fetc\u002Fhosts"," overrides DNS",[18,1677,1674],{}," is checked before DNS (controlled by ",[18,1680,1681],{},"nsswitch.conf",[18,1683,1684],{},"hosts: files dns","). A stale entry in ",[18,1687,1674],{}," can silently override the correct DNS record. ",[18,1690,697],{}," bypasses ",[18,1693,1674],{},"; ",[18,1696,1697],{},"getent hosts"," respects it.",[250,1700,1701,1706,1707,1710,1711,1713],{},[1564,1702,1703,1705],{},[18,1704,753],{}," is often auto-generated",": on systemd-resolved or NetworkManager systems, editing ",[18,1708,1709],{},"\u002Fetc\u002Fresolv.conf"," directly is overwritten on reboot. Use ",[18,1712,776],{}," or edit Netplan\u002FNetworkManager config.",[250,1715,1716,423,1721,1724,1725,1727,1728,1731],{},[1564,1717,1718,1720],{},[18,1719,1174],{}," can't do remote-to-remote",[18,1722,1723],{},"scp alice@server1:file alice@server2:file"," doesn't work directly — it tries to copy from server1 to your local machine then to server2. Use ",[18,1726,35],{}," or ",[18,1729,1730],{},"ssh alice@server1 \"scp file alice@server2:file\"",".",[250,1733,1734,423,1739,1742,1743,1747,1748,1751,1752,1755,1756,1758,1759,36],{},[1564,1735,1736,1738],{},[18,1737,35],{}," trailing slash matters",[18,1740,1741],{},"rsync dir\u002F dest\u002F"," copies the ",[1744,1745,1746],"em",{},"contents"," of ",[18,1749,1750],{},"dir",". ",[18,1753,1754],{},"rsync dir dest\u002F"," copies ",[18,1757,1750],{}," itself. Always dry-run first (",[18,1760,910],{},[250,1762,1763,1766,1767,1727,1769,1731],{},[1564,1764,1765],{},"Firewall can block ICMP (ping)",": a failed ping doesn't always mean the host is down. Try ",[18,1768,28],{},[18,1770,1771],{},"nc -zv host port",[250,1773,1774,423,1779,1782,1783,1731],{},[1564,1775,1776,1777],{},"Port conflicts on ",[18,1778,914],{},[18,1780,1781],{},"-p 8080:80"," fails if host port 8080 is already in use. Check with ",[18,1784,1785],{},"ss -tlnp | grep 8080",[38,1787,1789],{"id":1788},"spot-the-bug","🧠 Spot the Bug",[14,1791,1792],{},"An admin wants to test if a web server is reachable, but this command hangs for 60 seconds:",[43,1794,1795],{"language":45},[47,1796,1798],{"className":49,"code":1797,"language":45,"meta":51,"style":51},"curl http:\u002F\u002Finternal-server:80\u002F\n",[18,1799,1800],{"__ignoreMap":51},[55,1801,1802,1804],{"class":57,"line":58},[55,1803,28],{"class":61},[55,1805,1806],{"class":71}," http:\u002F\u002Finternal-server:80\u002F\n",[14,1808,1809,1812,1813,1816],{},[18,1810,1811],{},"ping internal-server"," works. ",[18,1814,1815],{},"dig internal-server"," returns the correct IP. What's likely wrong, and what should they check?",[1818,1819,1820,1824,1827,1863,1935],"details",{},[1821,1822,1823],"summary",{},"Answer",[14,1825,1826],{},"\"Connection timed out\" (curl hanging) + \"ping works\" means the host is reachable at the network layer (ICMP) but the TCP port (80) is not responding. Likely causes:",[1828,1829,1830,1845,1854],"ol",{},[250,1831,1832,1835,1836,1727,1839,1727,1842,1731],{},[1564,1833,1834],{},"Firewall is DROPping port 80"," (DROP = no response, hangs until timeout; REJECT = immediate \"connection refused\"). Check: ",[18,1837,1838],{},"sudo ufw status",[18,1840,1841],{},"sudo firewall-cmd --list-all",[18,1843,1844],{},"sudo iptables -L -n",[250,1846,1847,1850,1851,1731],{},[1564,1848,1849],{},"The web server isn't running"," and the firewall is set to DROP (not REJECT) — so instead of \"connection refused,\" it hangs. Check: ",[18,1852,1853],{},"ss -tlnp | grep :80",[250,1855,1856,1859,1860,1731],{},[1564,1857,1858],{},"A firewall on the path"," (not the server itself) is blocking port 80. Check: ",[18,1861,1862],{},"mtr --tcp --port 80 internal-server",[43,1864,1865],{"language":45},[47,1866,1868],{"className":49,"code":1867,"language":45,"meta":51,"style":51},"# Diagnostic flow:\nss -tlnp | grep :80               # is the server listening?\nnc -zv internal-server 80         # is the port open? (gives clearer error than curl)\nsudo iptables -L -n              # local firewall rules\nmtr --tcp --port 80 internal-server  # path diagnostic\n",[18,1869,1870,1875,1890,1904,1918],{"__ignoreMap":51},[55,1871,1872],{"class":57,"line":58},[55,1873,1874],{"class":174},"# Diagnostic flow:\n",[55,1876,1877,1879,1881,1883,1885,1887],{"class":57,"line":65},[55,1878,24],{"class":61},[55,1880,209],{"class":182},[55,1882,683],{"class":682},[55,1884,686],{"class":61},[55,1886,836],{"class":71},[55,1888,1889],{"class":174},"               # is the server listening?\n",[55,1891,1892,1894,1896,1899,1901],{"class":57,"line":91},[55,1893,1482],{"class":61},[55,1895,1485],{"class":182},[55,1897,1898],{"class":71}," internal-server",[55,1900,1490],{"class":182},[55,1902,1903],{"class":174},"         # is the port open? (gives clearer error than curl)\n",[55,1905,1906,1908,1911,1913,1915],{"class":57,"line":97},[55,1907,316],{"class":61},[55,1909,1910],{"class":71}," iptables",[55,1912,1090],{"class":182},[55,1914,1512],{"class":182},[55,1916,1917],{"class":174},"              # local firewall rules\n",[55,1919,1920,1922,1925,1928,1930,1932],{"class":57,"line":117},[55,1921,616],{"class":61},[55,1923,1924],{"class":182}," --tcp",[55,1926,1927],{"class":182}," --port",[55,1929,1490],{"class":182},[55,1931,1898],{"class":71},[55,1933,1934],{"class":174},"  # path diagnostic\n",[14,1936,1937,1938],{},"The key insight: ",[1564,1939,1940],{},"\"connection refused\" (fast) vs \"connection timed out\" (slow) tells you whether the firewall is REJECTing or DROPping, and whether anything is listening at all.",[1942,1943,1944],"style",{},"html pre.shiki code .sIsaT, html code.shiki .sIsaT{--shiki-default:#6F42C1;--shiki-github-dark:#B392F0}html pre.shiki code .sJ6F3, html code.shiki .sJ6F3{--shiki-default:#032F62;--shiki-github-dark:#9ECBFF}html pre.shiki code .ssxIu, html code.shiki .ssxIu{--shiki-default:#24292E;--shiki-github-dark:#E1E4E8}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}html.github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}html pre.shiki code .sdCPZ, html code.shiki .sdCPZ{--shiki-default:#6A737D;--shiki-github-dark:#6A737D}html pre.shiki code .snvgF, html code.shiki .snvgF{--shiki-default:#005CC5;--shiki-github-dark:#79B8FF}html pre.shiki code .sk71V, html code.shiki .sk71V{--shiki-default:#22863A;--shiki-github-dark:#85E89D}html pre.shiki code .svdQ7, html code.shiki .svdQ7{--shiki-default:#D73A49;--shiki-github-dark:#F97583}",{"title":51,"searchDepth":65,"depth":65,"links":1946},[1947,1948,1952,1953,1957,1959,1961,1962,1964,1967,1968,1969,1970],{"id":40,"depth":65,"text":41},{"id":161,"depth":65,"text":162,"children":1949},[1950,1951],{"id":303,"depth":91,"text":304},{"id":391,"depth":91,"text":392},{"id":564,"depth":65,"text":565},{"id":638,"depth":65,"text":639,"children":1954},[1955],{"id":749,"depth":91,"text":1956},"Edge Case: resolv.conf Is Often Auto-Generated",{"id":804,"depth":65,"text":1958},"Sockets — ss (Replaces netstat)",{"id":918,"depth":65,"text":1960},"HTTP — curl",{"id":1048,"depth":65,"text":1049},{"id":1168,"depth":65,"text":1963},"rsync (Preferred over scp)",{"id":1280,"depth":65,"text":1281,"children":1965},[1966],{"id":1392,"depth":91,"text":1393},{"id":1439,"depth":65,"text":1440},{"id":1557,"depth":65,"text":1558},{"id":1658,"depth":65,"text":1659},{"id":1788,"depth":65,"text":1789},"Networking is how your Linux box talks to other machines — via TCP\u002FIP, DNS, HTTP, SSH. This chapter covers the network stack, interface configuration (ip), routing, DNS, sockets (ss), and the everyday tools (curl, ssh, rsync).","md",{},"\u002Flinux\u002F10-networking-fundamentals",{"title":5,"description":1971},"linux\u002F10-networking-fundamentals","z-e0Jld3faa7oO1e16rtxK10cUnFPBIDncizsbJaoDM",1789924650005]