Instructions
- Attendance: Will be checked at the beginning of the Lab class
- Login Credentials:
- Username:
student - Password:
Siit@1992
- Username:
- Exercise Markers: The ✓ sign identifies your exercises
- Some exercises require a TA's signature to check your result
- Completion: Show Lab Sheet to TA when finishing all exercises
- Quiz: 10-minute quiz around the end of the Lab class (or when appropriate)
- Submission: Submit the last page to a TA at the end of the class
Overview
Maintaining a system's network is a task of network engineers. Their tasks include:
- Network configuration
- Monitoring
- Troubleshooting
As Linux takes over the network operating system, the roles of Linux network admin grow increasingly important.
Analogy: Think of network engineers as air traffic controllers - they need to configure flight paths (network routes), monitor all planes in the air (network traffic), and troubleshoot when problems arise (network issues).
Essential Networking Commands
Lab 3-4 Commands
| Command | Description |
|---|---|
arp | To view or add contents of the ARP cache |
ifconfig | To set up and display the network interfaces |
ping | To check if a specific computer is reachable or not and its traffic quality |
tcpdump | To capture packets exchanged through a specific NIC (command line interface) |
wireshark | To capture packets exchanged through a specific NIC and analyze these captured packets with tools provided (graphic user interface) |
DNS Records Commands
| Command | Description |
|---|---|
dig | To query the DNS name servers |
host | To find name to IP or IP to name in IPv4 or IPv6 and also query DNS records |
hostname | To view the hostname of the machine and to set the hostname |
nslookup | To find out DNS related query |
whois | To find out information about a domain |
Network Routes Commands
| Command | Description |
|---|---|
mtr | To trace routes in real time |
netstat | To display connection info, routing table information etc. |
route | To get the details of route table for your system and to manipulate it |
tracepath | Similar to traceroute but lesser popular and lesser options |
traceroute | To show number of hops taken to reach destination also determine packets traveling path |
Section 1: Commands Related to DNS Records
What is DNS?
The Domain Name System (DNS) is equivalent to a phonebook of the Internet:
- It maintains a directory of domain names (website names)
- Translates domain names to IP addresses
- Every time you use a domain name, a DNS service must translate the name into the corresponding IP address
Example: The domain name www.siit.tu.ac.th translates to 35.197.141.103
Analogy: DNS is like a phone book for the internet. Just as you look up a person's name to find their phone number, DNS looks up a website name to find its IP address. You remember "google.com" (easy for humans), but computers need "142.250.185.78" (the actual address).
1.1) hostname Command
Purpose: View your computer's hostname or set a new hostname
View Hostname
$ hostnameExample Output:
student@netlab09:~$ hostname
netlab09
student@netlab09:~$ _Set New Hostname (Restricted in Lab)
$ sudo hostname NewName⚠️ Note: According to the computer setup in this Lab, students are not allowed to use this command for setting hostname.
Analogy: The hostname is like your computer's nickname on the network - it's easier to remember "netlab09" than "192.178.18.1".
1.2) host Command
Purpose: A simple utility for performing DNS lookups, normally used to convert names to IP addresses
Command Syntax
$ host DomainNameExample
$ host www.siit.tu.ac.th
www.siit.tu.ac.th has address 35.197.141.103
student@netlab09:~$ _Key Points:
- Simple and straightforward DNS lookup tool
- Converts domain names → IP addresses
- Quick way to verify if a domain resolves correctly
1.3) nslookup Command
Purpose: Name server lookup - another tool used to perform DNS lookups
Command Syntax
$ nslookup DomainNameExample
$ nslookup www.tu.ac.th
Server: 192.178.18.1
Address: 192.178.18.1#53
Non-authoritative answer:
Name: www.tu.ac.th
Address: 203.131.212.198
student@netlab09:~$ _Understanding the Output:
- Server: The DNS server used for the query (192.178.18.1)
- Address: The DNS server's IP with port number (#53 is the standard DNS port)
- Non-authoritative answer: The response comes from a DNS cache, not the authoritative source
- Name: The domain name queried
- Address: The resolved IP address
Analogy:
nslookupis like calling directory assistance. The "Server" is the operator you're talking to, and they give you the "Address" (phone number) you're looking for. "Non-authoritative" means they looked it up in their records rather than being the official source.
Section 2: Commands Related to Network Routing
What is Routing?
Routing is a process performed by Layer 3 (Network Layer) devices to deliver packets by choosing an optimal path from one computer to another.
Key Concepts:
- The routing process directs forwarding packets based on routing tables
- Routing tables maintain a record of routes to various network destinations
Analogy: Routing is like GPS navigation for data packets. Just as GPS finds the best route from your home to a destination, routers use routing tables to find the best path for data to travel across networks.
2.1) route Command
Purpose: Shows and manipulates the IP routing table
View Routing Table
$ route -nOption:
-n= Show IP addresses instead of hostnames
Example Output
student@netlab09:~$ route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.178.18.1 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
student@netlab09:~$ _Understanding the Fields
| Field | Meaning |
|---|---|
| Destination | Target network or host |
| Gateway | The gateway (router) to use for this route |
| Genmask | The netmask for the destination |
| Flags | U = route is up, G = use specified gateway |
| Iface | Network Interface Card (NIC) name |
Special Values:
0.0.0.0means "not specified" or "any/all addresses"
Reading the Routing Table
Line 2 (Local Network):
192.178.18.0 0.0.0.0 255.255.255.0 U
- Meaning: If this computer sends packets to any IP addresses between 192.178.18.1 – 192.178.18.255, it can send directly to that IP address because they are in the same local area network (LAN)
Line 1 (Default Route):
0.0.0.0 192.178.18.1 0.0.0.0 UG
- Meaning: If this computer sends packets to other IP addresses (not in the local network), it must send these packets to the gateway 192.178.18.1, which will relay these packets to other routers/gateways
Analogy: Think of the routing table as a postal system's sorting rules:
- Line 2: "If the address is on our street (192.178.18.x), deliver directly"
- Line 1: "If the address is anywhere else (0.0.0.0), take it to the main post office (gateway 192.178.18.1) and let them figure out where it goes"
Without -n Option
student@netlab09:~$ route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default mylab.workgroup 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 * 255.255.255.0 U 0 0 0 eth0
student@netlab09:~$ _Shows hostnames instead of IP addresses (e.g., mylab.workgroup instead of 192.178.18.1)
2.2) traceroute Command
Purpose: A network troubleshooting utility that shows:
- The number of hops taken to reach a destination
- The packets' traveling path
- Can specify destination by domain name or IP address
How It Works
The traceroute command:
- Sends three UDP probe packets to each hop
- Listens for ICMP packets replied from servers/routers/gateways
- Incrementally increases the TTL (Time To Live) to discover each hop
Analogy: Traceroute is like leaving breadcrumbs on a journey. It sends out explorers (packets) that can only travel a certain distance before reporting back. First, it sends explorers that can only reach the first intersection (hop 1), then explorers that can reach the second intersection (hop 2), and so on, until reaching the final destination.
Basic Usage
$ traceroute IPaddressExample Output
$ traceroute 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
1 mylab.workgroup (192.178.18.1) 0.111 ms 0.084 ms 0.072 ms
2 10.10.98.1 (10.10.98.1) 0.492 ms 0.564 ms 0.556 ms
3 192.168.10.1 (192.168.10.1) 2.170 ms 2.704 ms 2.699 ms
4 192.168.30.3 (192.168.30.3) 2.679 ms 2.679 ms 2.687 ms
student@netlab09:~$ _Understanding the Output
First Line:
- Destination: 192.168.30.3
- Max hops: 30 (maximum number of hops traceroute will attempt)
- Packet size: 60 bytes
Each Hop Line:
- Hop number: Sequential number (1, 2, 3, 4...)
- Hostname: Name of the router/gateway
- IP address: In parentheses
- Three times: Roundtrip time (RTT) for each of the three probe packets sent
Example Interpretation:
- Hop 1: First router at 192.178.18.1, response times ~0.1ms (very fast, local network)
- Hop 2: Second router at 10.10.98.1, response times ~0.5ms
- Hop 3: Third router at 192.168.10.1, response times ~2.7ms
- Hop 4: Final destination at 192.168.30.3, response times ~2.7ms
Meaning: To send data packets to 192.168.30.3, packets will relay through:
Show Only IP Addresses
$ traceroute -n IPaddressOption: -n disables hostname resolution (shows only IP addresses)
Example:
$ traceroute -n 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
1 192.178.18.1 0.104 ms 0.081 ms 0.074 ms
2 10.10.98.1 0.301 ms 0.293 ms 0.342 ms
3 192.168.10.1 6.316 ms 6.335 ms 6.328 ms
4 192.168.30.3 8.753 ms 8.775 ms 9.843 ms
student@netlab09:~$ _Firewall Blocking (Important!)
Because of the Firewall in the SIIT network, UDP probe packets generated by traceroute will be blocked from the SIIT gateway.
Example of Blocked Traceroute:
instructor@netlab10:~$ traceroute www.tu.ac.th -n
traceroute to www.tu.ac.th (203.131.212.198), 30 hops max, 60 byte packets
1 192.178.18.1 0.083 ms 0.067 ms 0.065 ms
2 10.10.98.1 0.387 ms 0.387 ms 0.344 ms
3 192.168.10.1 4.346 ms 4.372 ms 4.367 ms
4 192.168.30.3 4.359 ms 4.352 ms 4.329 ms
5 * * *
6 * * *
7 * * *
8 * * *
9 * * *
10 *^C
instructor@netlab10:~$ _Understanding Asterisks (*):
- The asterisks (
* * *) show packet loss - The destination is not reached
- Reason: The Firewall has dropped these UDP probe packets
Analogy: The firewall is like a security checkpoint that stops certain types of messages. The UDP probe packets are like postcards - some security checkpoints don't allow postcards through, so they get thrown away (dropped), resulting in no response (asterisks).
Using TCP Packets (Alternative Method)
Some Firewalls allow other types of probe packets, such as TCP packets.
$ sudo traceroute IPaddress -T -nOptions:
-T= Use TCP SYN packets instead of UDP- Requires
sudofor TCP mode
Example:
instructor@netlab10:~$ sudo traceroute 203.131.212.198 -T -n
traceroute to 203.131.212.198 (203.131.212.198), 30 hops max, 60 byte packets
1 192.178.18.1 0.109 ms 0.095 ms 0.089 ms
2 10.10.98.1 0.439 ms 0.448 ms 0.510 ms
3 192.168.10.1 2.703 ms 3.154 ms 3.131 ms
4 192.168.30.3 3.142 ms 3.142 ms 3.128 ms
5 203.131.209.65 3.611 ms 3.620 ms 3.617 ms
6 203.131.212.198 3.753 ms 3.680 ms 3.540 ms
instructor@netlab10:~$ _⚠️ Lab Restriction: According to the computer setup in this Lab, students are not allowed to use the -T option.
2.3) netstat Command
Purpose: Network statistic - a command line tool for:
- Monitoring network connections (incoming and outgoing)
- Viewing routing tables
- Interface statistics
- And more
Display Protocol Statistics
$ netstat -sOption: -s displays statistics by protocols
Default protocols shown:
- TCP
- UDP
- ICMP
- IP
Example Output:
student@netlab09:~$ netstat -s
Ip:
17557 total packets received
2 with invalid addresses
0 forwarded
0 incoming packets discarded
17555 incoming packets delivered
13279 requests sent out
12 outgoing packets dropped
20 dropped because of missing route
Icmp:
607 ICMP messages received
0 input ICMP message failed.
ICMP input histogram:
destination unreachable: 57
timeout in transit: 446Key Metrics:
- Total packets received/sent: Overall network activity
- Invalid addresses: Malformed packets
- Packets dropped: Lost packets due to various reasons
- ICMP messages: Network control messages (errors, diagnostics)
Analogy:
netstat -sis like a detailed shipping report for a post office. It tells you how many packages were received, how many were sent out, how many had invalid addresses, and how many got lost along the way.
Display Routing Table
$ netstat -rOption: -r shows routing table information
Example Output:
student@netlab09:~$ netstat -r
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
default mylab.workgroup 0.0.0.0 UG 0 0 0 eth0
192.178.18.0 * 255.255.255.0 U 0 0 0 eth0
student@netlab09:~$ _Note: This is similar to the route command output
📝 Additional Options: More options are available for the netstat command which are not covered in this lab.
2.4) mtr Command
Purpose: "My TraceRoute" - a command line network diagnostic tool that combines the functionality of both ping and traceroute
Key Feature: View the traceroute report in real time with continuous updates
Command Syntax
$ mtr -n DestinationOption: -n shows IP addresses instead of hostnames
Example:
$ mtr -n 192.168.30.3⚠️ Exit: Press q or CTRL-C to quit
Example Output
My traceroute [v0.85]
netlab09 (0.0.0.0) Tue Feb 12 15:03:19 2019
Keys: Help Display mode Restart statistics Order of fields quit
Packets Pings
Host Loss% Snt Last Avg Best Wrst StDev
1. 192.178.18.1 0.0% 10 0.2 0.2 0.2 0.2 0.0
2. 10.10.98.1 0.0% 10 0.5 0.5 0.4 0.5 0.0
3. 192.168.10.1 0.0% 10 3.4 4.3 2.1 8.1 2.0
4. 192.168.30.3 0.0% 9 2.8 5.6 1.6 23.7 6.9
Understanding the Columns
| Column | Description |
|---|---|
| Host | IP address or hostname of each hop |
| Loss% | Percentage of packet loss at each hop |
| Snt | Number of packets sent |
| Last | Latency (roundtrip time) of the last packet sent |
| Avg | Average latency (roundtrip time) of all packets |
| Best | Best (shortest) latency of all packets sent |
| Wrst | Worst (longest) latency of all packets sent |
| StDev | Standard deviation of the latencies of all packets sent |
Interpreting the Results
Hop 1: 192.178.18.1
- Loss: 0% (perfect, no packet loss)
- Average latency: 0.2ms (very fast, local network)
- Very consistent (StDev = 0.0)
Hop 4: 192.168.30.3 (destination)
- Loss: 0% (all packets reached destination)
- Average latency: 5.6ms
- More variable (StDev = 6.9ms, Wrst = 23.7ms indicates occasional delays)
Analogy:
mtris like a live traffic report for your data. Whiletraceroutegives you a single snapshot of the route,mtrcontinuously monitors the route like a traffic camera, showing you real-time statistics about packet loss and delays at each hop. It's particularly useful for identifying network problems - if you see high packet loss or latency at a specific hop, you know where the problem is.
Use Cases:
- Identifying network bottlenecks
- Detecting intermittent connection issues
- Monitoring network quality in real-time
- Troubleshooting latency problems
Assignments
Assignment 1: Find IP Addresses
Objective: Find the IP address of the following domain names and those you are interested in.
| Domain Name | IP Address |
|---|---|
| www.google.com | |
Instructions:
- Use the
hostornslookupcommand to find IP addresses - Fill in the table with your findings
- Add additional domain names you're interested in
- Show your completed table to a TA for signature
Example Command:
$ host www.google.comor
$ nslookup www.google.comTA's Signature: ________________________
Assignment 2: Capture Packets Using Traceroute
Objective: Use Wireshark to verify and understand the mechanism of the traceroute command (how packets flow and discover the gateways).
Network Topology
The network setup for this assignment:
pc1 (192.178.18.1/24)
|
eth0
|
router1 (eth1: 10.10.98.2/24)
|
eth0 (10.10.98.1/24)
|
router2 (eth1: 192.168.10.2/24)
|
eth0 (192.168.10.1/24)
|
router3 (eth1: ?)
Important: Make sure the static route configuration is correct in PC1.
Static routing configuration should include:
0.0.0.0 192.178.18.1
10.0.0.0/8
Step-by-Step Instructions
Step 0: Setup Network
- Use IMUNES to create the network as shown in the topology diagram above
- Verify all connections are properly configured
- Ensure static routes are correct in PC1
Step 1: Start Wireshark
- Open Wireshark on PC1
- Select the appropriate network interface (eth0)
- Start capturing packets
Step 2: Run Traceroute Command
$ traceroute -n 192.168.10.1Expected Output:
traceroute to 192.168.10.1 (192.168.10.1), 30 hops max, 60 byte packets
1 192.178.18.1 0.130 ms 0.109 ms 0.101 ms
2 10.10.98.1 0.495 ms 0.504 ms 0.495 ms
3 192.168.10.1 2.019 ms 2.711 ms 2.735 ms
student@netlab09:~$ _Questions to Answer (Show to TA)
Hint: The details in this website might help you find the answer: Working of Traceroute using Wireshark
2.1) Discovery of Gateway 192.178.18.1
- Which packets are used to discover the gateway 192.178.18.1?
- Identify the corresponding ICMP packet sent back from this gateway
What to look for in Wireshark:
- Look for UDP packets with TTL = 1
- Find the corresponding ICMP "Time-to-live exceeded" messages
2.2) Discovery of Gateway 10.10.98.1
- Which packets are used to discover the gateway 10.10.98.1?
- Identify the corresponding ICMP packet sent back from this gateway
What to look for in Wireshark:
- Look for UDP packets with TTL = 2
- Find the corresponding ICMP "Time-to-live exceeded" messages
2.3) Discovery of Gateway 192.168.10.1
- Which packets are used to discover the gateway 192.168.10.1?
- Identify the corresponding ICMP packet sent back from this gateway
What to look for in Wireshark:
- Look for UDP packets with TTL = 3
- Find the corresponding ICMP messages (may be "Destination unreachable" since this is the final destination)
Understanding Traceroute Mechanism
How Traceroute Works with TTL:
-
First Probe (TTL = 1):
- Send UDP packet with TTL = 1
- First router decrements TTL to 0
- Router sends back ICMP "Time Exceeded" message
- This reveals the first hop (192.178.18.1)
-
Second Probe (TTL = 2):
- Send UDP packet with TTL = 2
- First router decrements to 1, forwards
- Second router decrements to 0
- Second router sends back ICMP "Time Exceeded"
- This reveals the second hop (10.10.98.1)
-
Third Probe (TTL = 3):
- Send UDP packet with TTL = 3
- Reaches destination (192.168.10.1)
- Destination sends ICMP "Port Unreachable" or similar
- This reveals the final destination
Analogy: TTL (Time To Live) is like a package with stamps. Each router removes one stamp. When a router removes the last stamp (TTL reaches 0), it sends a note back saying "Hey, I couldn't forward this because it ran out of stamps!" That's how traceroute discovers each router along the path.
TA's Signature: ________________________
Quiz Answer Sheet
Name and ID: _________________________________
Part 1: Lab Exercise Completion
When you complete all exercises, show your Lab Sheet to a TA to check in this box and sign the name.
☐ The student has finished all exercises.
TA's Signature: _____________________________
Part 2: Quiz Answers
Instruction: The quiz questions will be shown on the screen during the lab class. Write down your answers in the following table.
Question Types:
- Questions 1 – 4: Multiple-choice questions (1 point each)
- Questions 5 – 6: Short-answer questions (1 point each)
- Questions 7 – 8: Explanation questions (2 points each)
| Question | Answer |
|---|---|
| 1 | A ☐ B ☐ C ☐ D ☐ |
| 2 | A ☐ B ☐ C ☐ D ☐ |
| 3 | A ☐ B ☐ C ☐ D ☐ |
| 4 | A ☐ B ☐ C ☐ D ☐ |
| 5 | |
| 6 | |
| 7 | |
| 8 |
Total Score: _______
References
- L. Limwiwatkul, ITS352 Lecture/Lab Note, Academic Year 2/2017
- S. Gordon, Networking Lab Manual, 2015
Quick Reference Summary
DNS Lookup Commands Comparison
| Command | Primary Use | Output Detail |
|---|---|---|
hostname | View/set local hostname | Local system only |
host | Quick DNS lookup | Simple, concise |
nslookup | Detailed DNS query | Shows DNS server used |
dig | Advanced DNS queries | Most detailed |
Routing Commands Comparison
| Command | Primary Use | Real-time? |
|---|---|---|
route | View routing table | Static snapshot |
traceroute | Show path to destination | One-time trace |
mtr | Combined ping + traceroute | Yes, continuous |
netstat | Network statistics & connections | Static snapshot |
Common Command Options
-n= Show IP addresses instead of hostnames (faster, no DNS lookup)-s= Show statistics-r= Show routing information
Port Numbers to Remember
- DNS: Port 53
- HTTP: Port 80
- HTTPS: Port 443
Tips for Success
- Practice Commands: Try each command multiple times to understand the output
- Use
-nOption: When you don't need hostname resolution (faster results) - Understand TTL: Critical for understanding how traceroute works
- Read Wireshark Carefully: Look for patterns in packet types and TTL values
- Compare Tools: Use both
hostandnslookupto see different output formats
Study Tip: The best way to learn networking commands is to actually use them! Try tracing routes to different websites and comparing the results. Notice how some destinations require more hops than others, and observe how response times change based on geographic distance.
Common Issues and Solutions
Issue 1: Traceroute Shows Asterisks (**)
Cause: Firewall blocking UDP packets
Solution:
- Try TCP mode:
sudo traceroute -T destination - Or use
mtrwhich might work better - Some networks block ICMP, so this is normal
Issue 2: DNS Lookup Fails
Cause: DNS server unreachable or domain doesn't exist
Solution:
- Check your internet connection
- Verify the domain name spelling
- Try using a different DNS server
- Use
ping 8.8.8.8to test general connectivity
Issue 3: Permission Denied
Cause: Some commands require root privileges
Solution:
- Use
sudobefore the command - Example:
sudo traceroute -T destination
Key Takeaways
- DNS is essential: Every domain name must be resolved to an IP address
- Routing tables direct traffic: Like a GPS for network packets
- Multiple hops are normal: Data rarely travels directly to its destination
- Firewalls can block diagnostic tools: This is a security feature, not a bug
- Latency varies by hop: Geographic distance and network congestion affect speed
- Real-time monitoring matters: Tools like
mtrhelp identify intermittent issues
Final Thought: Networking is like a highway system for data. Understanding these tools helps you diagnose traffic jams (congestion), find alternative routes (routing), and understand why sometimes your data takes the scenic route!