<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/network/</link><description>Recent content in Network on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Mon, 07 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/network/index.xml" rel="self" type="application/rss+xml"/><item><title>ip: Network Setup and Diagnostics in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/ip-command-network-cli/</link><pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ip-command-network-cli/</guid><description>&lt;p&gt;When ifconfig returns nothing and configuring a route requires a separate command, that&amp;rsquo;s not a system bug. It&amp;rsquo;s iproute2 — the package that replaced net-tools in modern Linux distributions. The &lt;code&gt;ip&lt;/code&gt; utility from iproute2 is the standard interface for managing the Linux network stack. It covers interfaces, addresses, routes, ARP cache, routing policies, and namespace isolation.&lt;/p&gt;&#10;&lt;h2 id="why-iproute2-replaced-net-tools"&gt;Why iproute2 replaced net-tools&#10;&lt;/h2&gt;&#10;&lt;p&gt;net-tools (ifconfig, route, arp, netstat, nameif) originated in BSD and migrated to Linux in the 1990s. By the 2000s it became clear: they cannot handle VLAN, IPsec, QoS, multicast routing, or Policy Routing. Each task required a separate command with unrelated syntax.&lt;/p&gt;</description></item><item><title>nslookup and drill: DNS resolution in terminal</title><link>https://lead-devops.blackdevhub.online/en/posts/nslookup-drill-dns-resolution/</link><pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/nslookup-drill-dns-resolution/</guid><description>&lt;p&gt;The server won&amp;rsquo;t resolve a domain, but pings fly through. No familiar dig at hand — the BIOS is already loading a minimal busybox. Or on a host without bind-tools. nslookup and drill fill this gap: the first one is built into almost everything, the second gives more context when debugging.&lt;/p&gt;&#10;&lt;h2 id="nslookup-interactive-and-one-liner-modes"&gt;nslookup: interactive and one-liner modes&#10;&lt;/h2&gt;&#10;&lt;p&gt;nslookup ships with bind-utils and isc-dhcp-client. It works in two modes.&lt;/p&gt;</description></item><item><title>ethtool: network interface diagnostics and tuning</title><link>https://lead-devops.blackdevhub.online/en/posts/ethtool-diagnosis-tuning-network-interface/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ethtool-diagnosis-tuning-network-interface/</guid><description>&lt;p&gt;Network issues hide well — interface is up, IP is assigned, iptables is quiet, yet packet loss or micro-freezes only surface under load. ethtool gives direct access to hardware state, driver behavior, and offload mechanisms that neither &lt;code&gt;ip&lt;/code&gt; nor &lt;code&gt;netstat&lt;/code&gt; expose.&lt;/p&gt;&#10;&lt;h2 id="basic-output-link-state"&gt;Basic Output: Link State&#10;&lt;/h2&gt;&#10;&lt;p&gt;Installation is straightforward:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-f5ba18e4-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="5"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-f5ba18e4-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# RHEL/Alma/Rocky&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo dnf install ethtool -y&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Debian/Ubuntu&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install ethtool&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Running ethtool without flags prints a summary:&lt;/p&gt;</description></item><item><title>ss: socket statistics instead of deprecated netstat</title><link>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</guid><description>&lt;p&gt;When &lt;code&gt;netstat&lt;/code&gt; hangs on a server with tens of thousands of connections, it&amp;rsquo;s time to switch to &lt;code&gt;ss&lt;/code&gt;. Part of the &lt;code&gt;iproute2&lt;/code&gt; package, &lt;code&gt;ss&lt;/code&gt; queries the kernel directly via netlink instead of parsing &lt;code&gt;/proc/net/*&lt;/code&gt;. The result is instant output with minimal overhead.&lt;/p&gt;&#10;&lt;h2 id="why-switch-from-netstat"&gt;Why switch from netstat&#10;&lt;/h2&gt;&#10;&lt;p&gt;&lt;code&gt;netstat&lt;/code&gt; from &lt;code&gt;net-tools&lt;/code&gt; relies on a deprecated approach: it reads from &lt;code&gt;/proc/net/tcp&lt;/code&gt;, &lt;code&gt;/proc/net/unix&lt;/code&gt; and converts numeric IDs to symbolic names. On a server with active connections, this takes seconds and spikes CPU usage.&lt;/p&gt;</description></item><item><title>tcpdump and tshark: Packet Capture in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/tcpdump-tshark-cli-packet-capture/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/tcpdump-tshark-cli-packet-capture/</guid><description>&lt;p&gt;When debugging network issues in Linux infrastructure, &lt;code&gt;ping&lt;/code&gt; and &lt;code&gt;curl&lt;/code&gt; are not enough. Sometimes you need to see what is actually traveling over the wire. tcpdump is the standard tool for capturing packets from the CLI. tshark is its sibling from the Wireshark suite, convenient for scripting.&lt;/p&gt;&#10;&lt;h2 id="quick-start-with-tcpdump"&gt;Quick Start with tcpdump&#10;&lt;/h2&gt;&#10;&lt;p&gt;Check that packets are reaching the host:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-4d81bd54-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-4d81bd54-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;tcpdump -i eth0 host 10.0.0.5&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;The utility puts the interface into promiscuous mode and prints one line per packet passing through. By default it works with the first interface it finds, but specifying explicitly is better.&lt;/p&gt;</description></item><item><title>ngrep: grep for Network Packets in Real Time</title><link>https://lead-devops.blackdevhub.online/en/posts/ngrep-setevoy-grep/</link><pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ngrep-setevoy-grep/</guid><description>&lt;p&gt;Ngrep applies grep-style pattern matching to network packets. When you need to see exactly what two services are exchanging over the wire and tcpdump drowns you in noise, ngrep isolates the payload content you care about.&lt;/p&gt;&#10;&lt;h2 id="installation"&gt;Installation&#10;&lt;/h2&gt;&#10;&lt;p&gt;Ngrep ships in the standard repositories of most distributions.&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-b19d843d-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="8"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-b19d843d-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Debian/Ubuntu&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt install ngrep&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# RHEL/CentOS/Alma&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;yum install ngrep&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# macOS&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;brew install ngrep&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Running ngrep requires root privileges or the &lt;code&gt;CAP_NET_RAW&lt;/code&gt; and &lt;code&gt;CAP_NET_ADMIN&lt;/code&gt; capabilities.&lt;/p&gt;</description></item><item><title>Squid: Internet Forwarding to Remote VM</title><link>https://lead-devops.blackdevhub.online/en/posts/squid-proxy-remote-vm/</link><pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/squid-proxy-remote-vm/</guid><description>&lt;p&gt;Your VM in the cloud has no public IP or internet access is blocked via NAT, but the deployment needs wget/curl from inside. Squid on an intermediate host with a decent uplink solves this in ten minutes.&lt;/p&gt;&#10;&lt;h2 id="why-this-is-needed"&gt;Why This Is Needed&#10;&lt;/h2&gt;&#10;&lt;p&gt;I forward internet through Squid when a VM sits in an isolated network segment. An intermediate host with a public IP and network access becomes the proxy server. The application on the remote machine routes traffic through the tunnel.&lt;/p&gt;</description></item></channel></rss>