<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Networking on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/networking/</link><description>Recent content in Networking on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 18 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/networking/index.xml" rel="self" type="application/rss+xml"/><item><title>scp — Secure Copy Over SSH</title><link>https://lead-devops.blackdevhub.online/en/posts/scp/</link><pubDate>Fri, 18 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/scp/</guid><description>&lt;p&gt;scp — a utility for copying files over SSH using the SSH protocol. It works from the terminal, requires no extra server setup — just a running sshd and working authentication. In an era of rsync and bat, SCP survives as a simple tool for one-off transfers when you don&amp;rsquo;t want to deal with daemons or configuration files.&lt;/p&gt;&#10;&lt;h2 id="syntax-and-basic-scenarios"&gt;Syntax and Basic Scenarios&#10;&lt;/h2&gt;&#10;&lt;p&gt;General form:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-34b643d4-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-34b643d4-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;scp &lt;span class="o"&gt;[&lt;/span&gt;flags&lt;span class="o"&gt;]&lt;/span&gt; &lt;span class="nb"&gt;source&lt;/span&gt; destination&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Source and destination can be local paths or remote addresses in the format &lt;code&gt;user@host:path&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>nftables: Basic Rule Set</title><link>https://lead-devops.blackdevhub.online/en/posts/nftables-bazovyi-nabor-pravil/</link><pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/nftables-bazovyi-nabor-pravil/</guid><description>&lt;div class="td-callout td-callout--note" role="note"&gt;&#10; &lt;div class="td-callout__title"&gt;&lt;i class="td-callout__icon fa-solid fa-circle-info" aria-hidden="true"&gt;&lt;/i&gt;&lt;span class="td-callout__label"&gt;Note&lt;/span&gt;&lt;/div&gt;&#10; &lt;div class="td-callout__body"&gt;&#10;&lt;p&gt;All commands were verified on Debian/Ubuntu with the &lt;code&gt;nftables&lt;/code&gt; package and on RHEL/CentOS 8+. On older systems you may need &lt;code&gt;apt install nftables&lt;/code&gt; or &lt;code&gt;yum install nftables&lt;/code&gt;.&lt;/p&gt;&#10; &lt;/div&gt;&#10;&lt;/div&gt;&lt;p&gt;nftables replaced iptables, but documentation for a basic rule set is often scattered. Here is the reference I use when bringing up a firewall on a new host.&lt;/p&gt;&#10;&lt;h2 id="creating-the-inet-filter-table"&gt;Creating the inet filter table&#10;&lt;/h2&gt;&#10;&lt;p&gt;The &lt;code&gt;inet&lt;/code&gt; family table unifies IPv4 and IPv6 under a single namespace. This is the preferred approach when both stacks are active on the host.&lt;/p&gt;</description></item><item><title>Setting Up Your Own SSH Bastion Server</title><link>https://lead-devops.blackdevhub.online/en/posts/ssh-bastion-server/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ssh-bastion-server/</guid><description>&lt;h2 id="why-you-need-a-bastion-and-where-it-lives"&gt;Why You Need a Bastion and Where It Lives&#10;&lt;/h2&gt;&#10;&lt;p&gt;A bastion is the single entry point into a private network segment. Instead of exposing SSH on every server to the internet, you funnel traffic through one hardened host with a strict access policy. Typical layout: internet → bastion (public IP) → internal servers (only private subnet, SSH listening on &lt;code&gt;127.0.0.1&lt;/code&gt; or a private interface).&lt;/p&gt;&#10;&lt;p&gt;The bastion sits in a demilitarized zone (DMZ) or a public subnet provided by your hosting platform. Internal machines have no route to the internet through the bastion — return traffic flows only over established connections. This is a baseline model you can deploy on any VPS in about 15 minutes.&lt;/p&gt;</description></item><item><title>ProxyJump and bastion hosts via ~/.ssh/config</title><link>https://lead-devops.blackdevhub.online/en/posts/ssh-proxyjump-bastion-config/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ssh-proxyjump-bastion-config/</guid><description>&lt;p&gt;Sometimes a server sits in a private network with no public IP. The only entry point is a bastion host with a public address. Typing &lt;code&gt;ssh -J user@bastion user@private&lt;/code&gt; every time gets old fast. Here&amp;rsquo;s how to configure everything in &lt;code&gt;~/.ssh/config&lt;/code&gt; so you can reach private networks in one command.&lt;/p&gt;&#10;&lt;h2 id="why-you-need-a-bastion-host"&gt;Why you need a bastion host&#10;&lt;/h2&gt;&#10;&lt;p&gt;A bastion (jump host, jump box) is an intermediate server with public access that proxies connections to infrastructure without external IPs. The typical topology:&lt;/p&gt;</description></item><item><title>nftables: Modern Linux Firewall</title><link>https://lead-devops.blackdevhub.online/en/posts/nftables-modern-firewall-linux/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/nftables-modern-firewall-linux/</guid><description>&lt;div class="td-callout td-callout--warning" role="note"&gt;&#10; &lt;div class="td-callout__title"&gt;&lt;i class="td-callout__icon fa-solid fa-triangle-exclamation" aria-hidden="true"&gt;&lt;/i&gt;&lt;span class="td-callout__label"&gt;Warning&lt;/span&gt;&lt;/div&gt;&#10; &lt;div class="td-callout__body"&gt;&#10;&lt;p&gt;Before changing nftables, make sure you have physical or console access to the server. A misconfigured input chain can block SSH and lock you out.&lt;/p&gt;&#10; &lt;/div&gt;&#10;&lt;/div&gt;&lt;p&gt;nftables replaced iptables in the Linux kernel starting with version 3.13. If you&amp;rsquo;re still writing rules in iptables style, it&amp;rsquo;s time to reconsider. nftables performs better, has built-in dual-stack IPv4/IPv6 support, and lets you manage the entire ruleset as a whole instead of entering commands one by one.&lt;/p&gt;</description></item><item><title>socat: Forwarding Unix Sockets Over TCP</title><link>https://lead-devops.blackdevhub.online/en/posts/socat-unix-socket-tcp-forwarding/</link><pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/socat-unix-socket-tcp-forwarding/</guid><description>&lt;p&gt;Sometimes you need to reach a Unix socket from a host where that socket doesn&amp;rsquo;t physically exist. SSH tunnels won&amp;rsquo;t help — they only work with TCP ports. socat solves this: it opens a TCP listener and forwards connections to a Unix socket, and the client just connects over the network.&lt;/p&gt;&#10;&lt;h2 id="installation"&gt;Installation&#10;&lt;/h2&gt;&#10;&lt;p&gt;The package is available in every major distribution. On Debian/Ubuntu:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-553060c8-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-553060c8-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt install socat&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;On RHEL/CentOS:&lt;/p&gt;</description></item><item><title>dig: DNS Query Debugging in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/dig-dns-cli-debugging/</link><pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/dig-dns-cli-debugging/</guid><description>&lt;p&gt;DNS resolvers return the wrong address, clients don&amp;rsquo;t see updates, or it&amp;rsquo;s unclear which server is handling requests. &lt;code&gt;dig&lt;/code&gt; (Domain Information Groper) is the standard CLI tool for DNS diagnostics. Works on Linux, macOS, and Windows via WSL.&lt;/p&gt;&#10;&lt;h2 id="installation"&gt;Installation&#10;&lt;/h2&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-72265765-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="8"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-72265765-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Debian/Ubuntu&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt install dnsutils&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# RHEL/CentOS/Alma&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;dnf install bind-utils&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# macOS — ships with the system&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Windows — via WSL or ISC official binaries&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;h2 id="basic-flags"&gt;Basic Flags&#10;&lt;/h2&gt;&#10;&lt;p&gt;&lt;code&gt;dig&lt;/code&gt; has two classes of options: short flags (start with &lt;code&gt;-&lt;/code&gt;) control query behavior, while keywords with &lt;code&gt;+&lt;/code&gt; control output format.&lt;/p&gt;</description></item></channel></rss>