Concept and mechanism
Start by identifying source, destination, ports, protocol, interface, namespace, and time window. A host test does not necessarily represent an application in a network namespace with its own sockets and routes. ss helps observe sockets, but a missing listener in the wrong context does not prove global absence. ip route get resolves local selection for supplied parameters; it is not proof of remote connectivity or a business result. Keep local lookup, transport testing, and application testing separate. If IPv6 works and IPv4 does not, establish binding and effective IPV6_V6ONLY; the socket option can differ from the global default. Do not conclude that listening on:: guarantees every address family.
Guided application
To locate resets or lost traffic, correlate the same connection tuple and clocks across authorized observation points. A record from one endpoint can show the symptom without establishing origin. Bound collection, time, and required data while preserving relevant information and respecting permissions. In this course, all described captures and outputs are illustrative examples; no network command or real capture was executed. After a correction, establish handshake, business operation, expected data, and stability from the affected source. Retain evidence for investigation and regressions. If you lack namespace or device access, ask the responsible team for a specified collection instead of substituting a different test.
The host reaches the API but the container does not: compare actual context before declaring networking validated.
Common pitfalls
Different test as equivalent; local route as connectivity; reset as proven origin; handshake as complete recovery.
Related topics: Addresses, prefixes, and scope · Routes and next-hop resolution · Transport, acknowledgement, and messages
Reproduce affected-flow conditions and confirm the end-to-end result.
Reference: Linux network namespace isolation · DR TCP/IP 2026-09; TCP RFC 9293; IPv6 RFC 8200 with RFC 9673 update; Linux socket and iproute2 guidance