Lab 5

Updated 4 Oct 2026

Linux Lab 5 - DNS & Network Routing Commands - Cheat Sheet

Network Engineer Tasks

Network engineers are responsible for:

  • Network configuration: Setting up network paths and routing
  • Monitoring: Watching network traffic and performance
  • Troubleshooting: Fixing network connectivity issues

Analogy: Network engineers are like air traffic controllers - they configure flight paths (routes), monitor planes (network traffic), and troubleshoot problems.


Part 1: DNS (Domain Name System) Commands

What is DNS?

DNS = Domain Name System = "Phone book of the Internet"

Purpose:

  • Translates human-readable domain names → IP addresses
  • Computers use IP addresses, humans use domain names

Example:

  • Domain: npwitk.com → IP: 76.76.21.21 (example)
  • Domain: www.google.com → IP: 142.250.185.78
  • Domain: www.siit.tu.ac.th → IP: 35.197.141.103

Analogy: DNS is like a phone book. You remember names (domain names) easily, but to make a call, you need the phone number (IP address). DNS looks up the number for you automatically.


1.1 hostname Command

Purpose: View or set your computer's hostname

View Hostname

hostname

Example Output:

student@netlab09:~$ hostname
netlab09

What it shows: Your computer's name on the network

Set Hostname (Requires sudo)

sudo hostname NewName

⚠️ Lab Restriction: Students cannot use this command in lab

Your Computer's Hostname: Usually something like netlab09, student-pc, etc.

Analogy: Hostname is like your computer's nickname on the network - easier to remember than an IP address.


1.2 host Command

Purpose: Simple DNS lookup - convert domain name to IP address

Basic Syntax

host [domain_name]

Examples

Example 1: Your domain

$ host npwitk.com
npwitk.com has address 76.76.21.21
npwitk.com has IPv6 address 2606:4700:3034::ac43:bd4e
npwitk.com mail is handled by 10 mx1.improvmx.com.

Example 2: SIIT website

$ host www.siit.tu.ac.th
www.siit.tu.ac.th has address 35.197.141.103

Example 3: Google

$ host www.google.com
www.google.com has address 142.250.185.78
www.google.com has IPv6 address 2404:6800:4003:c00::64

What it shows:

  • IPv4 address (e.g., 76.76.21.21)
  • IPv6 address if available
  • Mail servers if configured

Characteristics:

  • Quick and simple
  • Minimal output
  • Easy to read

1.3 nslookup Command

Purpose: Name Server Lookup - detailed DNS query

Basic Syntax

nslookup [domain_name]

Examples

Example 1: Your domain

$ nslookup npwitk.com
Server:         192.178.18.1
Address:        192.178.18.1#53
 
Non-authoritative answer:
Name:   npwitk.com
Address: 76.76.21.21

Example 2: TU website

$ nslookup www.tu.ac.th
Server:         192.178.18.1
Address:        192.178.18.1#53
 
Non-authoritative answer:
Name:   www.tu.ac.th
Address: 203.131.212.198

Example 3: GitHub

$ nslookup github.com
Server:         192.178.18.1
Address:        192.178.18.1#53
 
Non-authoritative answer:
Name:   github.com
Address: 140.82.121.4

Understanding the Output

FieldMeaningExample
ServerDNS server that answered your query192.178.18.1
AddressDNS server's IP with port number192.178.18.1#53
#53Standard DNS portAlways 53
Non-authoritativeAnswer from DNS cache, not original sourceCommon for queries
NameDomain name you queriednpwitk.com
AddressResolved IP address76.76.21.21

Analogy: nslookup is like calling directory assistance. The "Server" is the operator you're talking to, and they give you the "Address" (phone number). "Non-authoritative" means they looked it up in their records rather than being the phone company itself.

Key Differences from host:

  • Shows which DNS server was used
  • More detailed output
  • Shows whether answer is authoritative or cached

DNS Commands Comparison

CommandOutput DetailBest ForSpeed
hostSimple, conciseQuick lookupsFast
nslookupDetailed, shows DNS serverTroubleshootingMedium
digVery detailedAdvanced debuggingSlower

Quick Test with Your Domain:

# Simple lookup
host npwitk.com
 
# Detailed lookup
nslookup npwitk.com
 
# Both should show IP: 76.76.21.21 (or current IP)

Part 2: Network Routing Commands

What is Routing?

Routing: Process of directing packets from source to destination through network

Key Concepts:

  • Performed by Layer 3 (Network Layer) devices
  • Uses routing tables to determine best path
  • Packets may travel through multiple hops (routers)

Analogy: Routing is like GPS navigation for data. Just as GPS finds the best route from your home to a destination, routers use routing tables to find the best path for data across networks.


2.1 route Command

Purpose: Display or modify the IP routing table

View Routing Table

route -n

Option: -n shows IP addresses instead of hostnames (faster)

Example Output

student@netlab09:~$ route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.178.18.1    0.0.0.0         UG    0      0        0 eth0
192.178.18.0    0.0.0.0         255.255.255.0   U     0      0        0 eth0

Understanding the Fields

FieldMeaningExample Value
DestinationTarget network or host192.178.18.0
GatewayRouter to use for this route192.178.18.1
GenmaskSubnet mask (netmask)255.255.255.0
FlagsRoute status (U=up, G=gateway)UG
IfaceNetwork interface to useeth0

Special Values:

  • 0.0.0.0 = Not specified / Any address / Default

Reading the Routing Table

Line 1: Default Route

0.0.0.0         192.178.18.1    0.0.0.0         UG

Meaning:

  • For any destination NOT in local network
  • Send packets to gateway 192.178.18.1
  • Gateway will forward packets to other networks

Line 2: Local Network

192.178.18.0    0.0.0.0         255.255.255.0   U

Meaning:

  • For destinations in 192.178.18.0/24 range
  • Send packets directly (no gateway needed)
  • They're on the same local network (LAN)

Example Routing Decisions:

# Destination: 192.178.18.50
# Decision: Use Line 2 (local network)
# Action: Send directly to 192.178.18.50
 
# Destination: 8.8.8.8 (Google DNS)
# Decision: Use Line 1 (default route)
# Action: Send to gateway 192.178.18.1
 
# Destination: npwitk.com (76.76.21.21)
# Decision: Use Line 1 (default route)
# Action: Send to gateway 192.178.18.1

Analogy: Routing table is like postal sorting rules:

  • Line 2: "If address is on our street, deliver directly"
  • Line 1: "If address is anywhere else, take to main post office (gateway)"

Without -n Option

$ route
Kernel IP routing table
Destination     Gateway             Genmask         Flags Metric Ref    Use Iface
default         mylab.workgroup     0.0.0.0         UG    0      0        0 eth0
192.178.18.0    *                   255.255.255.0   U     0      0        0 eth0

Differences:

  • Shows hostnames instead of IPs
  • default instead of 0.0.0.0
  • mylab.workgroup instead of 192.178.18.1
  • * means no gateway (direct connection)

2.2 traceroute Command

Purpose: Show the path packets take to reach a destination

What it does:

  • Shows each hop (router) along the path
  • Measures round-trip time (RTT) to each hop
  • Sends 3 probe packets to each hop

How Traceroute Works

Mechanism: Uses incrementing TTL (Time To Live)

  1. Hop 1: Send packet with TTL=1

    • First router decrements TTL to 0
    • Router sends back ICMP "Time Exceeded"
    • Reveals first hop
  2. Hop 2: Send packet with TTL=2

    • First router decrements to 1, forwards
    • Second router decrements to 0
    • Second router sends back ICMP
    • Reveals second hop
  3. Continue until destination reached

Analogy: TTL is like a package with stamps. Each router removes one stamp. When stamps run out (TTL=0), the router sends a note back saying "I couldn't forward this!" That's how traceroute discovers each router.

Basic Syntax

traceroute [destination]

Example 1: To Your Domain

$ traceroute npwitk.com
traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
 1  mylab.workgroup (192.178.18.1)  0.111 ms  0.084 ms  0.072 ms
 2  10.10.98.1 (10.10.98.1)  0.492 ms  0.564 ms  0.556 ms
 3  192.168.10.1 (192.168.10.1)  2.170 ms  2.704 ms  2.699 ms
 4  203.131.209.65 (203.131.209.65)  3.611 ms  3.620 ms  3.617 ms
 5  isp-router.example.com (1.2.3.4)  5.234 ms  5.123 ms  5.345 ms
 6  76.76.21.21 (76.76.21.21)  12.456 ms  12.234 ms  12.567 ms

Example 2: To Internal Network

$ traceroute 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
 1  mylab.workgroup (192.178.18.1)  0.111 ms  0.084 ms  0.072 ms
 2  10.10.98.1 (10.10.98.1)  0.492 ms  0.564 ms  0.556 ms
 3  192.168.10.1 (192.168.10.1)  2.170 ms  2.704 ms  2.699 ms
 4  192.168.30.3 (192.168.30.3)  2.679 ms  2.679 ms  2.687 ms

Understanding the Output

First Line:

traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
  • Destination: npwitk.com (resolved to 76.76.21.21)
  • Max hops: Will try up to 30 routers
  • Packet size: 60 bytes

Each Hop Line:

 1  mylab.workgroup (192.178.18.1)  0.111 ms  0.084 ms  0.072 ms
ComponentMeaning
1Hop number (sequence)
mylab.workgroupHostname of router
(192.178.18.1)IP address of router
0.111 msRTT of first probe packet
0.084 msRTT of second probe packet
0.072 msRTT of third probe packet

Interpreting RTT Values:

RTT RangeQualityTypical Cause
< 1 msExcellentLocal network
1-10 msVery GoodSame city/region
10-50 msGoodNearby countries
50-150 msAcceptableInternational
> 150 msSlowFar distance, congestion

Example Analysis:

 1  192.178.18.1      0.111 ms   ← Very fast (local)
 2  10.10.98.1        0.492 ms   ← Fast (campus network)
 3  192.168.10.1      2.170 ms   ← Good (same building)
 4  203.131.209.65    3.611 ms   ← Good (ISP gateway)
 5  isp-router        5.234 ms   ← Good (ISP network)
 6  76.76.21.21      12.456 ms   ← Excellent (npwitk.com)

Path Visualization:

Your PC → 192.178.18.1 → 10.10.98.1 → 192.168.10.1 → 
→ 203.131.209.65 → ISP Router → npwitk.com (76.76.21.21)

Show Only IP Addresses

traceroute -n [destination]

Option: -n disables hostname lookup (faster)

Example:

$ traceroute -n 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
 1  192.178.18.1  0.104 ms  0.081 ms  0.074 ms
 2  10.10.98.1  0.301 ms  0.293 ms  0.342 ms
 3  192.168.10.1  6.316 ms  6.335 ms  6.328 ms
 4  192.168.30.3  8.753 ms  8.775 ms  9.843 ms

Advantages:

  • Faster (no DNS lookups)
  • Cleaner output
  • Better for troubleshooting

Firewall Blocking

Problem: Many firewalls block UDP packets used by traceroute

Example of Blocked Traceroute:

$ traceroute npwitk.com
traceroute to npwitk.com (76.76.21.21), 30 hops max, 60 byte packets
 1  192.178.18.1  0.083 ms  0.067 ms  0.065 ms
 2  10.10.98.1  0.387 ms  0.387 ms  0.344 ms
 3  192.168.10.1  4.346 ms  4.372 ms  4.367 ms
 4  192.168.30.3  4.359 ms  4.352 ms  4.329 ms
 5  * * *
 6  * * *
 7  * * *
 8  * * *
^C

Understanding Asterisks (* * *):

  • No response received
  • Packets dropped by firewall
  • Destination not reached

Why this happens:

  • Firewalls block UDP probe packets
  • Security policy preventing traceroute
  • ICMP responses blocked

Analogy: Firewall is like a security checkpoint that stops certain messages. UDP probe packets are like postcards - some checkpoints don't allow postcards through.

Alternative: TCP Mode

Some firewalls allow TCP packets:

sudo traceroute -T -n [destination]

Options:

  • -T: Use TCP SYN packets (instead of UDP)
  • Requires sudo for TCP mode

Example:

$ sudo traceroute -T -n 76.76.21.21
traceroute to 76.76.21.21 (76.76.21.21), 30 hops max, 60 byte packets
 1  192.178.18.1  0.109 ms  0.095 ms  0.089 ms
 2  10.10.98.1  0.439 ms  0.448 ms  0.510 ms
 3  192.168.10.1  2.703 ms  3.154 ms  3.131 ms
 4  203.131.209.65  3.611 ms  3.620 ms  3.617 ms
 5  76.76.21.21  12.456 ms  12.234 ms  12.567 ms

⚠️ Lab Restriction: Students cannot use -T option in lab


2.3 netstat Command

Purpose: Network statistics - show network connections, routing, interface stats

Display Protocol Statistics

netstat -s

Option: -s shows statistics by protocol

Example Output:

$ netstat -s
Ip:
    17557 total packets received
    2 with invalid addresses
    0 forwarded
    0 incoming packets discarded
    17555 incoming packets delivered
    13279 requests sent out
    12 outgoing packets dropped
Icmp:
    607 ICMP messages received
    0 input ICMP message failed.
    ICMP input histogram:
        destination unreachable: 57
        timeout in transit: 446
Tcp:
    1234 active connections openings
    567 passive connection openings
    89 failed connection attempts

Key Metrics:

MetricMeaning
Total packets receivedAll incoming packets
Invalid addressesMalformed packets
Packets droppedLost packets
ICMP messagesNetwork control/error messages
Active connectionsOutgoing TCP connections
Passive connectionsIncoming TCP connections

Analogy: netstat -s is like a detailed shipping report for a post office - shows how many packages received, sent, lost, or had invalid addresses.

Display Routing Table

netstat -r

Option: -r shows routing table

Example Output:

$ netstat -r
Kernel IP routing table
Destination     Gateway             Genmask         Flags   MSS Window  irtt Iface
default         mylab.workgroup     0.0.0.0         UG        0 0          0 eth0
192.178.18.0    *                   255.255.255.0   U         0 0          0 eth0

Note: Similar to route command output

Common netstat Options

OptionDescriptionExample
-sProtocol statisticsnetstat -s
-rRouting tablenetstat -r
-aAll connectionsnetstat -a
-nNumeric (no DNS)netstat -n
-tTCP onlynetstat -t
-uUDP onlynetstat -u

2.4 mtr Command

Purpose: "My TraceRoute" - combines ping + traceroute with real-time updates

Key Feature: Continuous monitoring with live statistics

Basic Syntax

mtr -n [destination]

Option: -n shows IP addresses instead of hostnames

To Exit: Press q or CTRL-C

Example: To Your Domain

$ mtr -n npwitk.com

Example Output:

My traceroute  [v0.85]
netlab09 (0.0.0.0)                                      Tue Feb 12 15:03:19 2019
Keys:  Help   Display mode   Restart statistics   Order of fields   quit
                                                      Packets               Pings
 Host                                              Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. 192.178.18.1                                    0.0%    25    0.2   0.2   0.1   0.3   0.0
 2. 10.10.98.1                                      0.0%    25    0.5   0.5   0.4   0.7   0.1
 3. 192.168.10.1                                    0.0%    25    3.4   4.3   2.1   8.1   2.0
 4. 203.131.209.65                                  0.0%    25    4.2   4.5   3.8   6.2   0.8
 5. 76.76.21.21                                     0.0%    24   12.5  13.2  11.8  18.3   1.9

Understanding the Columns

ColumnDescription
HostIP address or hostname of each hop
Loss%Percentage of packet loss at this hop
SntNumber of packets sent
LastLatency of most recent packet
AvgAverage latency of all packets
BestBest (lowest) latency observed
WrstWorst (highest) latency observed
StDevStandard deviation (variability)

Interpreting Results

Hop 1: 192.178.18.1

Loss%: 0.0%     ← Perfect, no packet loss
Avg: 0.2ms      ← Very fast (local network)
StDev: 0.0      ← Very consistent

Analysis: Excellent connection to first hop

Hop 5: 76.76.21.21 (npwitk.com)

Loss%: 0.0%     ← No packet loss
Avg: 13.2ms     ← Good latency
Best: 11.8ms    ← Best case
Wrst: 18.3ms    ← Worst case (some variation)
StDev: 1.9      ← Moderate variability

Analysis: Good connection, some occasional delays

Problem Detection Example:

 Host                Loss%   Snt   Avg   Best  Wrst  StDev
 3. 192.168.10.1     25.0%   20   50.3   2.1  200.5   45.2

Red Flags:

  • High packet loss (25%)
  • High average latency (50ms)
  • Very high worst latency (200ms)
  • High variability (StDev 45.2) Diagnosis: Network congestion or hardware problem at hop 3

Analogy: mtr is like a live traffic report for your data. While traceroute gives you one snapshot, mtrcontinuously monitors like a traffic camera, showing real-time stats about packet loss and delays at each hop.

Use Cases:

  • Identify network bottlenecks
  • Detect intermittent connection issues
  • Monitor network quality in real-time
  • Troubleshoot latency problems

Traceroute Packet Analysis with Wireshark

Understanding Traceroute Mechanism

How Traceroute Discovers Routers:

Uses TTL (Time To Live) field in IP header:

  1. Probe 1 (TTL=1):
    • Send UDP packet with TTL=1
    • First router decrements TTL to 0
    • Router drops packet and sends ICMP "Time Exceeded"
    • Reveals: First router's IP
  2. Probe 2 (TTL=2):
    • Send UDP packet with TTL=2
    • First router: TTL=2→1, forwards
    • Second router: TTL=1→0, drops
    • Second router sends ICMP "Time Exceeded"
    • Reveals: Second router's IP
  3. Probe 3 (TTL=3):
    • Continue pattern...
    • Each router revealed by its ICMP response
  4. Destination Reached:
    • Final destination sends ICMP "Port Unreachable"
    • (Because traceroute uses non-existent high port)

Wireshark Analysis Steps

Network Topology Example:

pc1 (192.178.18.1/24)
    ↓
router1 (192.178.18.1 / 10.10.98.2)
    ↓
router2 (10.10.98.1 / 192.168.10.2)
    ↓
router3 (192.168.10.1 / ?)

Step 1: Start Wireshark on pc1

Step 2: Run traceroute

$ traceroute -n 192.168.10.1

Step 3: Apply Wireshark filter

udp || icmp

Expected Packet Sequence

Discovery of Hop 1 (192.178.18.1):

Packet 1: UDP (TTL=1)
  Source: 192.178.18.2
  Dest: 192.168.10.1
  TTL: 1

Packet 2: ICMP Time Exceeded
  Source: 192.178.18.1  ← First hop revealed!
  Dest: 192.178.18.2
  Type: 11 (Time Exceeded)

Discovery of Hop 2 (10.10.98.1):

Packet 3: UDP (TTL=2)
  Source: 192.178.18.2
  Dest: 192.168.10.1
  TTL: 2

Packet 4: ICMP Time Exceeded
  Source: 10.10.98.1    ← Second hop revealed!
  Dest: 192.178.18.2
  Type: 11 (Time Exceeded)

Discovery of Hop 3 (192.168.10.1):

Packet 5: UDP (TTL=3)
  Source: 192.178.18.2
  Dest: 192.168.10.1
  TTL: 3

Packet 6: ICMP Destination Unreachable
  Source: 192.168.10.1  ← Final destination!
  Dest: 192.178.18.2
  Type: 3 (Dest Unreachable)
  Code: 3 (Port Unreachable)

Wireshark Filter Tips

View all traceroute traffic:

udp || icmp

View only UDP probes:

udp

View only ICMP responses:

icmp

View specific TTL:

ip.ttl == 1
ip.ttl == 2
ip.ttl == 3

View Time Exceeded messages:

icmp.type == 11

View Port Unreachable:

icmp.type == 3 && icmp.code == 3