Cheatsheet
Network troubleshooting
An ordered diagnostic path with the command for each question, plus how to read the answer.
18 entries5 groupsRevised 11 Jan 2026
18/18
1 — Am I configured?
- Interfaces and state
ip -br addr - Default route present
ip route get 1.1.1.1 - Name resolution path
resolvectl status | sed -n '1,20p' - Linux firewall rules in effect
sudo nft list ruleset | head -40
2 — Can I resolve?
- A record
dig +short A example.org - Full chain from the configured resolver
dig +trace example.org - Ptr for an IP you found
dig +short -x 192.0.2.10 - Which resolver answered (avoid cache lies)
dig @127.0.0.53 example.org +noall +comments
3 — Can I connect?
- TCP handshake test with timing
time nc -zv 192.0.2.10 443 - Read the banner
nc -nv 192.0.2.10 22 - TLS parameters
openssl s_client -connect 192.0.2.10:443 -servername app.internal </dev/null | sed -n '1,25p' - Path with per-hop timing
traceroute -T -p 443 192.0.2.10ICMP-based traceroute is often filtered; TCP tells you about the real path
4 — What does the wire say?
- Bounded capture for one peer
sudo tcpdump -nn -i any -c 200 host 192.0.2.10 and port 443 - Only SYNs, to see half-open behaviour
sudo tcpdump -nn 'tcp[tcpflags] & (tcp-syn|tcp-rst) != 0' - Save for Wireshark
sudo tcpdump -i eth0 -w /tmp/diag.pcap -C 20 -W 3
5 — Slow service triage
- Retransmissions in the capture
tshark -r /tmp/diag.pcap -Y 'tcp.analysis.retransmission' | wc -l - Server-side window pressure
tshark -r /tmp/diag.pcap -Y 'tcp.analysis.zero_window' | wc -l - Compare RTT to total response time
tshark -r /tmp/diag.pcap -T fields -e tcp.handshake.time -e http.time