Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Linux network troubleshooting is easiest when each command answers one specific question: ip shows local configuration, dig checks name resolution, nc tests a port, and curl checks an application response. None proves the whole connection works. Use the 14 commands below to move from local setup toward the remote service, then capture packets only when simpler checks leave a gap.

Start with local network configuration

1. ip address: Do interfaces have addresses?

Run ip address show (or the shorter ip addr) to list interfaces and their assigned addresses. This tells you whether an address is configured locally; it does not show that a remote host is reachable.

2. ip route: Where will traffic be sent?

Run ip route show to inspect IPv4 routes and identify the default route. For IPv6, use ip -6 route show. A route in the table indicates the kernel’s route selection, not successful packet delivery through the gateway.

3. ip neigh: Is there a local neighbor entry?

Run ip neigh show to inspect the kernel’s neighbor table, useful for address resolution on a directly connected network. This is not a DNS lookup: it concerns local network neighbors, not translating an internet hostname into an address.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The ip utility has distinct address, route, and neighbor operations; choose the one that matches the question rather than treating its output as a general health check. See the ip manual.

Check local services and remote reachability

4. ss: Is a service listening locally?

Run ss -tuln to list listening TCP and UDP sockets without resolving service names. For TCP sockets more broadly, including their states, use ss -tan. A listening socket shows a local endpoint; it does not establish that a remote firewall permits access or that the application is responding correctly.

For example, if a service is expected on TCP port 8080, look for a listener with ss -tuln. If none appears, investigate the service configuration or whether it started before testing the network path.

5. ping: Does ICMP Echo get a reply?

Run ping -c 4 example.com to send four ICMP Echo requests and stop. A reply demonstrates that Echo traffic received a response along the tested path. No reply does not prove the host or its application is down: firewalls and network policies may suppress ICMP Echo.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Try an address as well as a hostname if you need to separate name resolution from the Echo test. The ping manual documents IPv4 and IPv6 operation.

6. traceroute: Which hops respond along the path?

Run traceroute -n example.com to display responding hops without looking up their names. Traceroute implementations can use different probe methods, including UDP, ICMP, or TCP; options vary. Asterisks or missing hops may mean routers filter or rate-limit probes, so they do not identify conclusively where an application connection fails.

7. tracepath: Is path MTU information available?

Run tracepath example.com to trace the path and discover path MTU information where intermediate routers report it. The documented utility does not require superuser privileges. Address family and router behavior affect what it can show; use it when path MTU is relevant rather than as a substitute for an application-level test. See the tracepath manual and traceroute manual.

Check name resolution and application responses

8. dig: What address does DNS return?

Run dig example.com A to query for an IPv4 address, or dig example.com AAAA for an IPv6 address, subject to the installed implementation and resolver configuration. A DNS answer only confirms the lookup result; it does not test whether the destination service accepts connections or works.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. nslookup: Make a basic DNS lookup

Run nslookup example.com where the command is installed. It is a familiar basic lookup, but available options and output depend on the implementation. Like dig, it checks name resolution rather than service health.

If one lookup command is missing, try the other if installed, or install the appropriate package for your distribution. Do not infer that DNS is broken solely because a particular utility is absent.

10. curl: Does an HTTP endpoint respond?

Run curl -I https://example.com to request response headers from an HTTP endpoint. An HTTP response gives more application-layer information than a ping, but it does not reveal packet-level details. Also, a response code or header is not proof that every page feature or backend dependency is healthy.

curl transfers data to or from a server and supports multiple protocols depending on how it was built. The current curl project manual reviewed describes curl 8.23.0; that version number is not a claim about the version packaged by any particular Linux distribution. See the curl manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

11. wget: Can a file be downloaded?

Run wget https://example.com/file to download a specific URL non-interactively. This tests a URL transfer and writes the downloaded file locally; use an intentional target rather than attempting to copy a whole site. GNU Wget is documented as a non-interactive download utility. See the GNU Wget manual.

12. nc: Can a TCP connection reach a host and port?

A common OpenBSD netcat-style check is nc -vz example.com 443. It attempts a TCP connection to port 443 and reports whether the connection succeeds. This helps distinguish a port-connectivity problem from a DNS lookup, but a successful TCP handshake does not prove that the application protocol is healthy.

Netcat variants differ, so flags such as -vz are not portable across every implementation. The cited OpenBSD-style manual also documents listeners and UDP connections; consult the local manual before relying on variant-specific syntax. Use nc -l only when intentionally setting up a local listener. See the nc manual.

Inspect packets and Ethernet device settings

13. tcpdump: What packets are visible on an interface?

Run sudo tcpdump -ni any 'port 53' to observe traffic matching DNS port 53 on systems that support the any pseudo-interface. The -n option avoids name resolution in the display and -i selects an interface. Capture permissions may be required; a narrow filter keeps the output focused.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can write a capture for later analysis, but packet captures may expose sensitive information. Limit what you collect, protect capture files, and remove them when no longer needed. The tcpdump manual describes packet filters and capture output.

14. ethtool: What does a wired device report?

Run sudo ethtool eth0, substituting the actual interface name, to query a network device. The utility reports driver and hardware settings, particularly for wired Ethernet. It can also control settings; treat configuration-changing options as advanced administration, not as casual diagnostic commands. See the ethtool manual.

Choose a command by the symptom

Question Start with What the result does not establish
Does this machine have an address? ip address show Remote reachability
Which route is selected? ip route show or ip -6 route show Successful packet delivery
Is a local service listening? ss -tuln Remote firewall access or application correctness
Does the name resolve? dig or nslookup Service availability
Does ICMP Echo get a reply? ping -c 4 host That a silent host or service is down
Can a remote TCP port be reached? nc -vz host port That the application protocol works
Does an HTTP endpoint respond? curl -I URL Packet-level causes or full application health
What matching packets are visible? tcpdump Traffic outside the selected interface or filter
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical troubleshooting sequence

  1. Check local setup. Use ip address show, then ip route show (and ip -6 route show for IPv6) to see addresses and route selection.
  2. Separate DNS from connectivity. Query the hostname with dig or nslookup; then test a resolved destination as appropriate. Remember that a DNS answer is not a service test.
  3. Test the relevant layer. Use ping for ICMP Echo, nc for a TCP port, or curl for an HTTP response. Select the test that matches the failing application rather than expecting one command to prove everything.
  4. Investigate path symptoms. Use traceroute or tracepath when hop behavior or path MTU matters. Missing probe responses are not conclusive evidence of an application failure location.
  5. Go deeper only if needed. Inspect local listeners with ss, packets with a narrow tcpdump filter, or wired device details with ethtool.

Common command problems and what to do

  • “Command not found”: the utility may not be installed. Install the package provided for your Linux distribution, or use another installed tool that answers the same question. Package names differ across distributions.
  • Permission denied: some packet captures and device queries require elevated privileges. Use sudo only for the specific operation and only if you are authorized to administer the machine.
  • ping gets no replies: ICMP Echo may be filtered. Check the route and test the actual service with an appropriate TCP or HTTP command before concluding it is unavailable.
  • traceroute shows asterisks: a router may not answer or may rate-limit probes. Try a supported probe method if the installed implementation offers one, and compare with a test to the actual destination service.
  • nc rejects an option: netcat implementations differ. Check man nc and adjust for the installed variant rather than assuming OpenBSD flags are universal.
  • tcpdump shows nothing: verify the interface, filter, and privilege level. The any interface is not supported on every system; select the relevant interface if necessary.
  • Unexpected DNS results: resolver configuration and installed implementations affect lookups. Compare A and AAAA queries if the issue may be address-family-specific, then test the resulting endpoint separately.

Or skip the browser setup

For developers who need screenshots of web pages rather than shell-level network diagnostics, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns an image or PDF; see the ScreenshotNeo API documentation.

cURL example:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie and consent banners like a visitor before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sign up for 1,000 free screenshots a month, with no card.

Frequently Asked Questions

Do Linux network commands work the same on every distribution?

No. Utilities may be absent, options and output can vary by implementation, and privileges depend on the operation. Check the local manual page for version-specific syntax.

Can a successful ping prove that a website is working?

No. Ping tests ICMP Echo, not the website’s application response. Use an HTTP request such as curl for an HTTP endpoint.

Which command should I use to test a specific TCP port?

A common OpenBSD netcat-style invocation is nc -vz host port, but netcat flags vary by implementation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.