Linux Lab 5 - DNS & Network Routing Commands - Cheat Sheet
Network Engineer Tasks
Network engineers are responsible for:
- Network configuration: Setting up network paths and routing
- Monitoring: Watching network traffic and performance
- Troubleshooting: Fixing network connectivity issues
Analogy: Network engineers are like air traffic controllers - they configure flight paths (routes), monitor planes (network traffic), and troubleshoot problems.
Part 1: DNS (Domain Name System) Commands
What is DNS?
DNS = Domain Name System = "Phone book of the Internet"
Purpose:
- Translates human-readable domain names → IP addresses
- Computers use IP addresses, humans use domain names
Example:
- Domain:
npwitk.com→ IP:76.76.21.21(example) - Domain:
www.google.com→ IP:142.250.185.78 - Domain:
www.siit.tu.ac.th→ IP:35.197.141.103
Analogy: DNS is like a phone book. You remember names (domain names) easily, but to make a call, you need the phone number (IP address). DNS looks up the number for you automatically.
1.1 hostname Command
Purpose: View or set your computer's hostname
View Hostname
hostnameExample Output:
student@netlab09:~$ hostname
netlab09What it shows: Your computer's name on the network
Set Hostname (Requires sudo)
sudo hostname NewName⚠️ Lab Restriction: Students cannot use this command in lab
Your Computer's Hostname: Usually something like netlab09, student-pc, etc.
Analogy: Hostname is like your computer's nickname on the network - easier to remember than an IP address.
1.2 host Command
Purpose: Simple DNS lookup - convert domain name to IP address
Basic Syntax
host [domain_name]Examples
Example 1: Your domain
$ host npwitk.com
npwitk.com has address 76.76.21.21
npwitk.com has IPv6 address 2606:4700:3034::ac43:bd4e
npwitk.com mail is handled by 10 mx1.improvmx.com.Example 2: SIIT website
$ host www.siit.tu.ac.th
www.siit.tu.ac.th has address 35.197.141.103Example 3: Google
$ host www.google.com
www.google.com has address 142.250.185.78
www.google.com has IPv6 address 2404:6800:4003:c00::64What it shows:
- IPv4 address (e.g., 76.76.21.21)
- IPv6 address if available
- Mail servers if configured
Characteristics:
- Quick and simple
- Minimal output
- Easy to read
1.3 nslookup Command
Purpose: Name Server Lookup - detailed DNS query
Basic Syntax
nslookup [domain_name]Examples
Example 1: Your domain
$ nslookup npwitk.com
Server: 192.178.18.1
Address: 192.178.18.1#53
Non-authoritative answer:
Name: npwitk.com
Address: 76.76.21.21Example 2: TU website
$ nslookup www.tu.ac.th
Server: 192.178.18.1
Address: 192.178.18.1#53
Non-authoritative answer:
Name: www.tu.ac.th
Address: 203.131.212.198Example 3: GitHub
$ nslookup github.com
Server: 192.178.18.1
Address: 192.178.18.1#53
Non-authoritative answer:
Name: github.com
Address: 140.82.121.4Understanding the Output
| Field | Meaning | Example |
|---|---|---|
| Server | DNS server that answered your query | 192.178.18.1 |
| Address | DNS server's IP with port number | 192.178.18.1#53 |
| #53 | Standard DNS port | Always 53 |
| Non-authoritative | Answer from DNS cache, not original source | Common for queries |
| Name | Domain name you queried | npwitk.com |
| Address | Resolved IP address | 76.76.21.21 |
Analogy:
nslookupis like calling directory assistance. The "Server" is the operator you're talking to, and they give you the "Address" (phone number). "Non-authoritative" means they looked it up in their records rather than being the phone company itself.
Key Differences from host:
- Shows which DNS server was used
- More detailed output
- Shows whether answer is authoritative or cached
DNS Commands Comparison
| Command | Output Detail | Best For | Speed |
|---|---|---|---|
host | Simple, concise | Quick lookups | Fast |
nslookup | Detailed, shows DNS server | Troubleshooting | Medium |
dig | Very detailed | Advanced debugging | Slower |
Quick Test with Your Domain:
# Simple lookup
host npwitk.com
# Detailed lookup
nslookup npwitk.com
# Both should show IP: 76.76.21.21 (or current IP)Part 2: Network Routing Commands
What is Routing?
Routing: Process of directing packets from source to destination through network
Key Concepts:
- Performed by Layer 3 (Network Layer) devices
- Uses routing tables to determine best path
- Packets may travel through multiple hops (routers)
Analogy: Routing is like GPS navigation for data. Just as GPS finds the best route from your home to a destination, routers use routing tables to find the best path for data across networks.
2.1 route Command
Purpose: Display or modify the IP routing table
View Routing Table
route -nOption: -n shows IP addresses instead of hostnames (faster)
Example Output
student@netlab09:~$ route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.178.18.1 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0Understanding the Fields
| Field | Meaning | Example Value |
|---|---|---|
| Destination | Target network or host | 192.178.18.0 |
| Gateway | Router to use for this route | 192.178.18.1 |
| Genmask | Subnet mask (netmask) | 255.255.255.0 |
| Flags | Route status (U=up, G=gateway) | UG |
| Iface | Network interface to use | eth0 |
Special Values:
0.0.0.0= Not specified / Any address / Default
Reading the Routing Table
Line 1: Default Route
0.0.0.0 192.178.18.1 0.0.0.0 UG
Meaning:
- For any destination NOT in local network
- Send packets to gateway 192.178.18.1
- Gateway will forward packets to other networks
Line 2: Local Network
192.178.18.0 0.0.0.0 255.255.255.0 U
Meaning:
- For destinations in 192.178.18.0/24 range
- Send packets directly (no gateway needed)
- They're on the same local network (LAN)
Example Routing Decisions:
# Destination: 192.178.18.50
# Decision: Use Line 2 (local network)
# Action: Send directly to 192.178.18.50
# Destination: 8.8.8.8 (Google DNS)
# Decision: Use Line 1 (default route)
# Action: Send to gateway 192.178.18.1
# Destination: npwitk.com (76.76.21.21)
# Decision: Use Line 1 (default route)
# Action: Send to gateway 192.178.18.1Analogy: Routing table is like postal sorting rules:
- Line 2: "If address is on our street, deliver directly"
- Line 1: "If address is anywhere else, take to main post office (gateway)"
Without -n Option
$ route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default mylab.workgroup 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 * 255.255.255.0 U 0 0 0 eth0Differences:
- Shows hostnames instead of IPs
defaultinstead of0.0.0.0mylab.workgroupinstead of192.178.18.1*means no gateway (direct connection)
2.2 traceroute Command
Purpose: Show the path packets take to reach a destination
What it does:
- Shows each hop (router) along the path
- Measures round-trip time (RTT) to each hop
- Sends 3 probe packets to each hop
How Traceroute Works
Mechanism: Uses incrementing TTL (Time To Live)
-
Hop 1: Send packet with TTL=1
- First router decrements TTL to 0
- Router sends back ICMP "Time Exceeded"
- Reveals first hop
-
Hop 2: Send packet with TTL=2
- First router decrements to 1, forwards
- Second router decrements to 0
- Second router sends back ICMP
- Reveals second hop
-
Continue until destination reached
Analogy: TTL is like a package with stamps. Each router removes one stamp. When stamps run out (TTL=0), the router sends a note back saying "I couldn't forward this!" That's how traceroute discovers each router.
Basic Syntax
traceroute [destination]Example 1: To Your Domain
$ traceroute npwitk.com
traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
1 mylab.workgroup (192.178.18.1) 0.111 ms 0.084 ms 0.072 ms
2 10.10.98.1 (10.10.98.1) 0.492 ms 0.564 ms 0.556 ms
3 192.168.10.1 (192.168.10.1) 2.170 ms 2.704 ms 2.699 ms
4 203.131.209.65 (203.131.209.65) 3.611 ms 3.620 ms 3.617 ms
5 isp-router.example.com (1.2.3.4) 5.234 ms 5.123 ms 5.345 ms
6 76.76.21.21 (76.76.21.21) 12.456 ms 12.234 ms 12.567 msExample 2: To Internal Network
$ traceroute 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
1 mylab.workgroup (192.178.18.1) 0.111 ms 0.084 ms 0.072 ms
2 10.10.98.1 (10.10.98.1) 0.492 ms 0.564 ms 0.556 ms
3 192.168.10.1 (192.168.10.1) 2.170 ms 2.704 ms 2.699 ms
4 192.168.30.3 (192.168.30.3) 2.679 ms 2.679 ms 2.687 msUnderstanding the Output
First Line:
traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
- Destination: npwitk.com (resolved to 76.76.21.21)
- Max hops: Will try up to 30 routers
- Packet size: 60 bytes
Each Hop Line:
1 mylab.workgroup (192.178.18.1) 0.111 ms 0.084 ms 0.072 ms
| Component | Meaning |
|---|---|
1 | Hop number (sequence) |
mylab.workgroup | Hostname of router |
(192.178.18.1) | IP address of router |
0.111 ms | RTT of first probe packet |
0.084 ms | RTT of second probe packet |
0.072 ms | RTT of third probe packet |
Interpreting RTT Values:
| RTT Range | Quality | Typical Cause |
|---|---|---|
| < 1 ms | Excellent | Local network |
| 1-10 ms | Very Good | Same city/region |
| 10-50 ms | Good | Nearby countries |
| 50-150 ms | Acceptable | International |
| > 150 ms | Slow | Far distance, congestion |
Example Analysis:
1 192.178.18.1 0.111 ms ← Very fast (local)
2 10.10.98.1 0.492 ms ← Fast (campus network)
3 192.168.10.1 2.170 ms ← Good (same building)
4 203.131.209.65 3.611 ms ← Good (ISP gateway)
5 isp-router 5.234 ms ← Good (ISP network)
6 76.76.21.21 12.456 ms ← Excellent (npwitk.com)
Path Visualization:
Your PC → 192.178.18.1 → 10.10.98.1 → 192.168.10.1 →
→ 203.131.209.65 → ISP Router → npwitk.com (76.76.21.21)
Show Only IP Addresses
traceroute -n [destination]Option: -n disables hostname lookup (faster)
Example:
$ traceroute -n 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
1 192.178.18.1 0.104 ms 0.081 ms 0.074 ms
2 10.10.98.1 0.301 ms 0.293 ms 0.342 ms
3 192.168.10.1 6.316 ms 6.335 ms 6.328 ms
4 192.168.30.3 8.753 ms 8.775 ms 9.843 msAdvantages:
- Faster (no DNS lookups)
- Cleaner output
- Better for troubleshooting
Firewall Blocking
Problem: Many firewalls block UDP packets used by traceroute
Example of Blocked Traceroute:
$ traceroute npwitk.com
traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
1 192.178.18.1 0.083 ms 0.067 ms 0.065 ms
2 10.10.98.1 0.387 ms 0.387 ms 0.344 ms
3 192.168.10.1 4.346 ms 4.372 ms 4.367 ms
4 192.168.30.3 4.359 ms 4.352 ms 4.329 ms
5 * * *
6 * * *
7 * * *
8 * * *
^CUnderstanding Asterisks (* * *):
- No response received
- Packets dropped by firewall
- Destination not reached
Why this happens:
- Firewalls block UDP probe packets
- Security policy preventing traceroute
- ICMP responses blocked
Analogy: Firewall is like a security checkpoint that stops certain messages. UDP probe packets are like postcards - some checkpoints don't allow postcards through.
Alternative: TCP Mode
Some firewalls allow TCP packets:
sudo traceroute -T -n [destination]Options:
-T: Use TCP SYN packets (instead of UDP)- Requires
sudofor TCP mode
Example:
$ sudo traceroute -T -n 76.76.21.21
traceroute to 76.76.21.21 (76.76.21.21), 30 hops max, 60 byte packets
1 192.178.18.1 0.109 ms 0.095 ms 0.089 ms
2 10.10.98.1 0.439 ms 0.448 ms 0.510 ms
3 192.168.10.1 2.703 ms 3.154 ms 3.131 ms
4 203.131.209.65 3.611 ms 3.620 ms 3.617 ms
5 76.76.21.21 12.456 ms 12.234 ms 12.567 ms⚠️ Lab Restriction: Students cannot use -T option in lab
2.3 netstat Command
Purpose: Network statistics - show network connections, routing, interface stats
Display Protocol Statistics
netstat -sOption: -s shows statistics by protocol
Example Output:
$ netstat -s
Ip:
17557 total packets received
2 with invalid addresses
0 forwarded
0 incoming packets discarded
17555 incoming packets delivered
13279 requests sent out
12 outgoing packets dropped
Icmp:
607 ICMP messages received
0 input ICMP message failed.
ICMP input histogram:
destination unreachable: 57
timeout in transit: 446
Tcp:
1234 active connections openings
567 passive connection openings
89 failed connection attemptsKey Metrics:
| Metric | Meaning |
|---|---|
| Total packets received | All incoming packets |
| Invalid addresses | Malformed packets |
| Packets dropped | Lost packets |
| ICMP messages | Network control/error messages |
| Active connections | Outgoing TCP connections |
| Passive connections | Incoming TCP connections |
Analogy:
netstat -sis like a detailed shipping report for a post office - shows how many packages received, sent, lost, or had invalid addresses.
Display Routing Table
netstat -rOption: -r shows routing table
Example Output:
$ netstat -r
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
default mylab.workgroup 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 * 255.255.255.0 U 0 0 0 eth0Note: Similar to route command output
Common netstat Options
| Option | Description | Example |
|---|---|---|
-s | Protocol statistics | netstat -s |
-r | Routing table | netstat -r |
-a | All connections | netstat -a |
-n | Numeric (no DNS) | netstat -n |
-t | TCP only | netstat -t |
-u | UDP only | netstat -u |
2.4 mtr Command
Purpose: "My TraceRoute" - combines ping + traceroute with real-time updates
Key Feature: Continuous monitoring with live statistics
Basic Syntax
mtr -n [destination]Option: -n shows IP addresses instead of hostnames
To Exit: Press q or CTRL-C
Example: To Your Domain
$ mtr -n npwitk.comExample Output:
My traceroute [v0.85]
netlab09 (0.0.0.0) Tue Feb 12 15:03:19 2019
Keys: Help Display mode Restart statistics Order of fields quit
Packets Pings
Host Loss% Snt Last Avg Best Wrst StDev
1. 192.178.18.1 0.0% 25 0.2 0.2 0.1 0.3 0.0
2. 10.10.98.1 0.0% 25 0.5 0.5 0.4 0.7 0.1
3. 192.168.10.1 0.0% 25 3.4 4.3 2.1 8.1 2.0
4. 203.131.209.65 0.0% 25 4.2 4.5 3.8 6.2 0.8
5. 76.76.21.21 0.0% 24 12.5 13.2 11.8 18.3 1.9
Understanding the Columns
| Column | Description |
|---|---|
| Host | IP address or hostname of each hop |
| Loss% | Percentage of packet loss at this hop |
| Snt | Number of packets sent |
| Last | Latency of most recent packet |
| Avg | Average latency of all packets |
| Best | Best (lowest) latency observed |
| Wrst | Worst (highest) latency observed |
| StDev | Standard deviation (variability) |
Interpreting Results
Hop 1: 192.178.18.1
Loss%: 0.0% ← Perfect, no packet loss
Avg: 0.2ms ← Very fast (local network)
StDev: 0.0 ← Very consistent
Analysis: Excellent connection to first hop
Hop 5: 76.76.21.21 (npwitk.com)
Loss%: 0.0% ← No packet loss
Avg: 13.2ms ← Good latency
Best: 11.8ms ← Best case
Wrst: 18.3ms ← Worst case (some variation)
StDev: 1.9 ← Moderate variability
Analysis: Good connection, some occasional delays
Problem Detection Example:
Host Loss% Snt Avg Best Wrst StDev
3. 192.168.10.1 25.0% 20 50.3 2.1 200.5 45.2
Red Flags:
- High packet loss (25%)
- High average latency (50ms)
- Very high worst latency (200ms)
- High variability (StDev 45.2) Diagnosis: Network congestion or hardware problem at hop 3
Analogy:
mtris like a live traffic report for your data. Whiletraceroutegives you one snapshot,mtrcontinuously monitors like a traffic camera, showing real-time stats about packet loss and delays at each hop.
Use Cases:
- Identify network bottlenecks
- Detect intermittent connection issues
- Monitor network quality in real-time
- Troubleshoot latency problems
Traceroute Packet Analysis with Wireshark
Understanding Traceroute Mechanism
How Traceroute Discovers Routers:
Uses TTL (Time To Live) field in IP header:
- Probe 1 (TTL=1):
- Send UDP packet with TTL=1
- First router decrements TTL to 0
- Router drops packet and sends ICMP "Time Exceeded"
- Reveals: First router's IP
- Probe 2 (TTL=2):
- Send UDP packet with TTL=2
- First router: TTL=2→1, forwards
- Second router: TTL=1→0, drops
- Second router sends ICMP "Time Exceeded"
- Reveals: Second router's IP
- Probe 3 (TTL=3):
- Continue pattern...
- Each router revealed by its ICMP response
- Destination Reached:
- Final destination sends ICMP "Port Unreachable"
- (Because traceroute uses non-existent high port)
Wireshark Analysis Steps
Network Topology Example:
pc1 (192.178.18.1/24)
↓
router1 (192.178.18.1 / 10.10.98.2)
↓
router2 (10.10.98.1 / 192.168.10.2)
↓
router3 (192.168.10.1 / ?)
Step 1: Start Wireshark on pc1
Step 2: Run traceroute
$ traceroute -n 192.168.10.1Step 3: Apply Wireshark filter
udp || icmp
Expected Packet Sequence
Discovery of Hop 1 (192.178.18.1):
Packet 1: UDP (TTL=1)
Source: 192.178.18.2
Dest: 192.168.10.1
TTL: 1
Packet 2: ICMP Time Exceeded
Source: 192.178.18.1 ← First hop revealed!
Dest: 192.178.18.2
Type: 11 (Time Exceeded)
Discovery of Hop 2 (10.10.98.1):
Packet 3: UDP (TTL=2)
Source: 192.178.18.2
Dest: 192.168.10.1
TTL: 2
Packet 4: ICMP Time Exceeded
Source: 10.10.98.1 ← Second hop revealed!
Dest: 192.178.18.2
Type: 11 (Time Exceeded)
Discovery of Hop 3 (192.168.10.1):
Packet 5: UDP (TTL=3)
Source: 192.178.18.2
Dest: 192.168.10.1
TTL: 3
Packet 6: ICMP Destination Unreachable
Source: 192.168.10.1 ← Final destination!
Dest: 192.178.18.2
Type: 3 (Dest Unreachable)
Code: 3 (Port Unreachable)
Wireshark Filter Tips
View all traceroute traffic:
udp || icmp
View only UDP probes:
udp
View only ICMP responses:
icmp
View specific TTL:
ip.ttl == 1
ip.ttl == 2
ip.ttl == 3
View Time Exceeded messages:
icmp.type == 11
View Port Unreachable:
icmp.type == 3 && icmp.code == 3