← Linux administration for operations
11 / 12 · 50 MIN

Diagnose networking in the application context

Trace resolution, routing, TCP, TLS, and HTTP without confusing a local observation with service recovery.

Describe a reproducible flow

Start with the failing operation: process, namespace, source address, destination name and port, time, and expected outcome. A host test is useful for comparison but may use another resolver or routing table. In a container, establish the effective view before changing the host. If the application maintains a cache or uses its own resolver, a getent lookup does not automatically reproduce that behavior. Record which conditions you matched and which remain different. This prevents another team receiving only “the network works” while the real consumer still cannot obtain the required result.

Select a route with the same selectors

A routing lookup answers the local decision for the supplied parameters. ip route get can include source, mark, and other selectors; it does not send a packet to demonstrate arrival at the destination. Within the selected table, prefix specificity matters: a /24 may be chosen over a /16 with a lower metric. Before that table lookup, policy-routing rules may direct marked traffic to another route set. Compare application and test selectors, including numeric rule priority. A correction should stay within the authorized flow and include return-path validation, without experimentally deleting global policies.

Interpret sockets without inventing the cause

A LISTEN port has an address and context. Listening only on 127.0.0.1 is not equivalent to exposing the port on the interface used by a remote client. With IPv6, the presence of [::] does not alone establish whether the socket accepts IPv4; check the effective option and behavior. SYN-SENT shows an attempt that has not completed. Immediate refusal and timeout guide different investigations but do not automatically identify a firewall, server, or responsible team. A local denial correlated with EACCES is another concrete clue. Link each observation to time and flow, keeping collection bounded and avoiding unnecessary sensitive content.

Separate name, destination, and TLS trust

In a migration test, you may want to contact a candidate IP while retaining the client-facing name. For a direct request without proxy or redirects, curl --resolve overrides resolution for a name/port pair while preserving the named URL. Keep authorized trust and TLS verification enabled. Changing only the Host header in an IP-based URL is not the same check. In s_client, SNI and hostname verification are also distinct decisions; diagnostic mode may continue after errors, so verification status and fail-on-error behavior must be explicit. Record the relevant certificate, name, and result without collecting secrets.

Measure phases and accept the right outcome

The curl timings used in this module are milestones from the start. On a new direct connection, subtracting time_connect from time_appconnect helps estimate the interval between completed TCP and TLS. That interval is not a measurement of server CPU. A three-second connection limit within a ten-second overall limit does not create a thirteen-second budget. After establishing the session, validate HTTP status and content against the contract. Receiving a 503 body may be transfer success and functional failure. The diagnostic worksheet should separate observation, hypothesis, next check, and the consumer’s recovery criterion.

ip rule show
ip route get 192.0.2.40
ss -lnt
getent hosts api.example.test
IN PRACTICE

Fictional example: an unmarked test uses main and succeeds; the application uses fwmark 0x20 and table 200 and times out. Reproduce selectors in the lookup and compare the route without treating success on another flow as application recovery.

Common pitfalls

Testing in the wrong context; comparing different marks; assuming dual stack; using -k for TLS acceptance; adding cumulative times; confusing received HTTP with functional outcome.

Related topics: Separate DNS, connections, TLS, and the application · Shell: arguments, pipelines, and exit codes · Isolate resources and establish readiness on Linux · Recover filesystems and publish data safely

Take this idea with you

Evidence establishes only the observed flow and phase. Recovery requires reproducing the consumer and validating its outcome.

Create account

Reference: ip-route(8) · DR Linux 2026.4; networking and Bash manuals reviewed 2026-10-01; cgroup v2 and upstream systemd manuals reviewed 2026-10-01; RHEL 10 examples; Linux man-pages 6.19; OpenSSL 3.5