Concept and mechanism
A socket listening on 127.0.0.1 accepts within loopback scope; opening firewall ports does not change that bind. Before exposing the listener, confirm the design: a local proxy may be the only authorized entry point. Use ss to observe sockets and connect address and port to the process. With several interfaces, ip addr shows addresses but does not itself determine which source will be selected for a destination. ip route get lets you query that decision; with policy routing, consider relevant source, rules, and context. Avoid deleting a default route merely because it appears first.
Guided application
The application’s resolution mechanism also matters. dig queries DNS, while getent follows databases configured through NSS. If the application uses NSS and /etc/hosts contains an old address, a correct DNS test may not represent the real path. With dual stack, test IPv4 and IPv6 separately while preserving hostname and TLS context. Success in one family does not demonstrate success in the other. In SSH, a changed host key after replacement is plausible, but the ticket does not authenticate the new key. Confirm the fingerprint through an authenticated channel and update only the necessary trust. Do not erase every known key or globally disable verification to bypass a warning.
The partner rejects the observed source IP: query the route to that destination before proposing firewall changes.
Common pitfalls
Open port as external listener; address list as routing decision; dig as a test of every application; planned change as authenticated key.
Related topics: Time, filtering, bonds, and proxies · Storage, mounts, and recovery
Reproduce client context and collect evidence at each flow boundary.
Reference: ss(8) · LFCS current five-domain outline; exact edition date unconfirmed