Lab 5 - Essential Networking Commands & Tools

Updated 4 Oct 2026

Instructions

  • Attendance: Will be checked at the beginning of the Lab class
  • Login Credentials:
    • Username: student
    • Password: Siit@1992
  • Exercise Markers: The ✓ sign identifies your exercises
    • Some exercises require a TA's signature to check your result
  • Completion: Show Lab Sheet to TA when finishing all exercises
  • Quiz: 10-minute quiz around the end of the Lab class (or when appropriate)
  • Submission: Submit the last page to a TA at the end of the class

Overview

Maintaining a system's network is a task of network engineers. Their tasks include:

  • Network configuration
  • Monitoring
  • Troubleshooting

As Linux takes over the network operating system, the roles of Linux network admin grow increasingly important.

Analogy: Think of network engineers as air traffic controllers - they need to configure flight paths (network routes), monitor all planes in the air (network traffic), and troubleshoot when problems arise (network issues).


Essential Networking Commands

Lab 3-4 Commands

CommandDescription
arpTo view or add contents of the ARP cache
ifconfigTo set up and display the network interfaces
pingTo check if a specific computer is reachable or not and its traffic quality
tcpdumpTo capture packets exchanged through a specific NIC (command line interface)
wiresharkTo capture packets exchanged through a specific NIC and analyze these captured packets with tools provided (graphic user interface)

DNS Records Commands

CommandDescription
digTo query the DNS name servers
hostTo find name to IP or IP to name in IPv4 or IPv6 and also query DNS records
hostnameTo view the hostname of the machine and to set the hostname
nslookupTo find out DNS related query
whoisTo find out information about a domain

Network Routes Commands

CommandDescription
mtrTo trace routes in real time
netstatTo display connection info, routing table information etc.
routeTo get the details of route table for your system and to manipulate it
tracepathSimilar to traceroute but lesser popular and lesser options
tracerouteTo show number of hops taken to reach destination also determine packets traveling path

What is DNS?

The Domain Name System (DNS) is equivalent to a phonebook of the Internet:

  • It maintains a directory of domain names (website names)
  • Translates domain names to IP addresses
  • Every time you use a domain name, a DNS service must translate the name into the corresponding IP address

Example: The domain name www.siit.tu.ac.th translates to 35.197.141.103

Analogy: DNS is like a phone book for the internet. Just as you look up a person's name to find their phone number, DNS looks up a website name to find its IP address. You remember "google.com" (easy for humans), but computers need "142.250.185.78" (the actual address).


1.1) hostname Command

Purpose: View your computer's hostname or set a new hostname

View Hostname

$ hostname

Example Output:

student@netlab09:~$ hostname
netlab09
student@netlab09:~$ _

Set New Hostname (Restricted in Lab)

$ sudo hostname NewName

⚠️ Note: According to the computer setup in this Lab, students are not allowed to use this command for setting hostname.

Analogy: The hostname is like your computer's nickname on the network - it's easier to remember "netlab09" than "192.178.18.1".


1.2) host Command

Purpose: A simple utility for performing DNS lookups, normally used to convert names to IP addresses

Command Syntax

$ host DomainName

Example

$ host www.siit.tu.ac.th
www.siit.tu.ac.th has address 35.197.141.103
student@netlab09:~$ _

Key Points:

  • Simple and straightforward DNS lookup tool
  • Converts domain names → IP addresses
  • Quick way to verify if a domain resolves correctly

1.3) nslookup Command

Purpose: Name server lookup - another tool used to perform DNS lookups

Command Syntax

$ nslookup DomainName

Example

$ nslookup www.tu.ac.th
Server:         192.178.18.1
Address:        192.178.18.1#53
 
Non-authoritative answer:
Name:   www.tu.ac.th
Address: 203.131.212.198
 
student@netlab09:~$ _

Understanding the Output:

  • Server: The DNS server used for the query (192.178.18.1)
  • Address: The DNS server's IP with port number (#53 is the standard DNS port)
  • Non-authoritative answer: The response comes from a DNS cache, not the authoritative source
  • Name: The domain name queried
  • Address: The resolved IP address

Analogy: nslookup is like calling directory assistance. The "Server" is the operator you're talking to, and they give you the "Address" (phone number) you're looking for. "Non-authoritative" means they looked it up in their records rather than being the official source.


What is Routing?

Routing is a process performed by Layer 3 (Network Layer) devices to deliver packets by choosing an optimal path from one computer to another.

Key Concepts:

  • The routing process directs forwarding packets based on routing tables
  • Routing tables maintain a record of routes to various network destinations

Analogy: Routing is like GPS navigation for data packets. Just as GPS finds the best route from your home to a destination, routers use routing tables to find the best path for data to travel across networks.


2.1) route Command

Purpose: Shows and manipulates the IP routing table

View Routing Table

$ route -n

Option:

  • -n = Show IP addresses instead of hostnames

Example Output

student@netlab09:~$ route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.178.18.1    0.0.0.0         UG    0      0        0 eth0
192.178.18.0    0.0.0.0         255.255.255.0   U     0      0        0 eth0
student@netlab09:~$ _

Understanding the Fields

FieldMeaning
DestinationTarget network or host
GatewayThe gateway (router) to use for this route
GenmaskThe netmask for the destination
FlagsU = route is up, G = use specified gateway
IfaceNetwork Interface Card (NIC) name

Special Values:

  • 0.0.0.0 means "not specified" or "any/all addresses"

Reading the Routing Table

Line 2 (Local Network):

192.178.18.0    0.0.0.0         255.255.255.0   U
  • Meaning: If this computer sends packets to any IP addresses between 192.178.18.1 – 192.178.18.255, it can send directly to that IP address because they are in the same local area network (LAN)

Line 1 (Default Route):

0.0.0.0         192.178.18.1    0.0.0.0         UG
  • Meaning: If this computer sends packets to other IP addresses (not in the local network), it must send these packets to the gateway 192.178.18.1, which will relay these packets to other routers/gateways

Analogy: Think of the routing table as a postal system's sorting rules:

  • Line 2: "If the address is on our street (192.178.18.x), deliver directly"
  • Line 1: "If the address is anywhere else (0.0.0.0), take it to the main post office (gateway 192.178.18.1) and let them figure out where it goes"

Without -n Option

student@netlab09:~$ route
Kernel IP routing table
Destination     Gateway             Genmask         Flags Metric Ref    Use Iface
default         mylab.workgroup     0.0.0.0         UG    0      0        0 eth0
192.178.18.0    *                   255.255.255.0   U     0      0        0 eth0
student@netlab09:~$ _

Shows hostnames instead of IP addresses (e.g., mylab.workgroup instead of 192.178.18.1)


2.2) traceroute Command

Purpose: A network troubleshooting utility that shows:

  • The number of hops taken to reach a destination
  • The packets' traveling path
  • Can specify destination by domain name or IP address

How It Works

The traceroute command:

  1. Sends three UDP probe packets to each hop
  2. Listens for ICMP packets replied from servers/routers/gateways
  3. Incrementally increases the TTL (Time To Live) to discover each hop

Analogy: Traceroute is like leaving breadcrumbs on a journey. It sends out explorers (packets) that can only travel a certain distance before reporting back. First, it sends explorers that can only reach the first intersection (hop 1), then explorers that can reach the second intersection (hop 2), and so on, until reaching the final destination.

Basic Usage

$ traceroute IPaddress

Example Output

$ traceroute 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
 1  mylab.workgroup (192.178.18.1)  0.111 ms  0.084 ms  0.072 ms
 2  10.10.98.1 (10.10.98.1)  0.492 ms  0.564 ms  0.556 ms
 3  192.168.10.1 (192.168.10.1)  2.170 ms  2.704 ms  2.699 ms
 4  192.168.30.3 (192.168.30.3)  2.679 ms  2.679 ms  2.687 ms
student@netlab09:~$ _

Understanding the Output

First Line:

  • Destination: 192.168.30.3
  • Max hops: 30 (maximum number of hops traceroute will attempt)
  • Packet size: 60 bytes

Each Hop Line:

  • Hop number: Sequential number (1, 2, 3, 4...)
  • Hostname: Name of the router/gateway
  • IP address: In parentheses
  • Three times: Roundtrip time (RTT) for each of the three probe packets sent

Example Interpretation:

  • Hop 1: First router at 192.178.18.1, response times ~0.1ms (very fast, local network)
  • Hop 2: Second router at 10.10.98.1, response times ~0.5ms
  • Hop 3: Third router at 192.168.10.1, response times ~2.7ms
  • Hop 4: Final destination at 192.168.30.3, response times ~2.7ms

Meaning: To send data packets to 192.168.30.3, packets will relay through: 192.178.18.1→10.10.98.1→192.168.10.1→192.168.30.3\boxed{\text{192.178.18.1} \rightarrow \text{10.10.98.1} \rightarrow \text{192.168.10.1} \rightarrow \text{192.168.30.3}}

Show Only IP Addresses

$ traceroute -n IPaddress

Option: -n disables hostname resolution (shows only IP addresses)

Example:

$ traceroute -n 192.168.30.3
traceroute to 192.168.30.3 (192.168.30.3), 30 hops max, 60 byte packets
 1  192.178.18.1  0.104 ms  0.081 ms  0.074 ms
 2  10.10.98.1  0.301 ms  0.293 ms  0.342 ms
 3  192.168.10.1  6.316 ms  6.335 ms  6.328 ms
 4  192.168.30.3  8.753 ms  8.775 ms  9.843 ms
student@netlab09:~$ _

Firewall Blocking (Important!)

Because of the Firewall in the SIIT network, UDP probe packets generated by traceroute will be blocked from the SIIT gateway.

Example of Blocked Traceroute:

instructor@netlab10:~$ traceroute www.tu.ac.th -n
traceroute to www.tu.ac.th (203.131.212.198), 30 hops max, 60 byte packets
 1  192.178.18.1  0.083 ms  0.067 ms  0.065 ms
 2  10.10.98.1  0.387 ms  0.387 ms  0.344 ms
 3  192.168.10.1  4.346 ms  4.372 ms  4.367 ms
 4  192.168.30.3  4.359 ms  4.352 ms  4.329 ms
 5  * * *
 6  * * *
 7  * * *
 8  * * *
 9  * * *
10  *^C
instructor@netlab10:~$ _

Understanding Asterisks (*):

  • The asterisks (* * *) show packet loss
  • The destination is not reached
  • Reason: The Firewall has dropped these UDP probe packets

Analogy: The firewall is like a security checkpoint that stops certain types of messages. The UDP probe packets are like postcards - some security checkpoints don't allow postcards through, so they get thrown away (dropped), resulting in no response (asterisks).

Using TCP Packets (Alternative Method)

Some Firewalls allow other types of probe packets, such as TCP packets.

$ sudo traceroute IPaddress -T -n

Options:

  • -T = Use TCP SYN packets instead of UDP
  • Requires sudo for TCP mode

Example:

instructor@netlab10:~$ sudo traceroute 203.131.212.198 -T -n
traceroute to 203.131.212.198 (203.131.212.198), 30 hops max, 60 byte packets
 1  192.178.18.1  0.109 ms  0.095 ms  0.089 ms
 2  10.10.98.1  0.439 ms  0.448 ms  0.510 ms
 3  192.168.10.1  2.703 ms  3.154 ms  3.131 ms
 4  192.168.30.3  3.142 ms  3.142 ms  3.128 ms
 5  203.131.209.65  3.611 ms  3.620 ms  3.617 ms
 6  203.131.212.198  3.753 ms  3.680 ms  3.540 ms
instructor@netlab10:~$ _

⚠️ Lab Restriction: According to the computer setup in this Lab, students are not allowed to use the -T option.


2.3) netstat Command

Purpose: Network statistic - a command line tool for:

  • Monitoring network connections (incoming and outgoing)
  • Viewing routing tables
  • Interface statistics
  • And more

Display Protocol Statistics

$ netstat -s

Option: -s displays statistics by protocols

Default protocols shown:

  • TCP
  • UDP
  • ICMP
  • IP

Example Output:

student@netlab09:~$ netstat -s
Ip:
    17557 total packets received
    2 with invalid addresses
    0 forwarded
    0 incoming packets discarded
    17555 incoming packets delivered
    13279 requests sent out
    12 outgoing packets dropped
    20 dropped because of missing route
Icmp:
    607 ICMP messages received
    0 input ICMP message failed.
    ICMP input histogram:
        destination unreachable: 57
        timeout in transit: 446

Key Metrics:

  • Total packets received/sent: Overall network activity
  • Invalid addresses: Malformed packets
  • Packets dropped: Lost packets due to various reasons
  • ICMP messages: Network control messages (errors, diagnostics)

Analogy: netstat -s is like a detailed shipping report for a post office. It tells you how many packages were received, how many were sent out, how many had invalid addresses, and how many got lost along the way.

Display Routing Table

$ netstat -r

Option: -r shows routing table information

Example Output:

student@netlab09:~$ netstat -r
Kernel IP routing table
Destination     Gateway             Genmask         Flags   MSS Window  irtt Iface
default         mylab.workgroup     0.0.0.0         UG        0 0          0 eth0
192.178.18.0    *                   255.255.255.0   U         0 0          0 eth0
student@netlab09:~$ _

Note: This is similar to the route command output

📝 Additional Options: More options are available for the netstat command which are not covered in this lab.


2.4) mtr Command

Purpose: "My TraceRoute" - a command line network diagnostic tool that combines the functionality of both ping and traceroute

Key Feature: View the traceroute report in real time with continuous updates

Command Syntax

$ mtr -n Destination

Option: -n shows IP addresses instead of hostnames

Example:

$ mtr -n 192.168.30.3

⚠️ Exit: Press q or CTRL-C to quit

Example Output

My traceroute  [v0.85]
netlab09 (0.0.0.0)                                      Tue Feb 12 15:03:19 2019
Keys:  Help   Display mode   Restart statistics   Order of fields   quit
                                                      Packets               Pings
 Host                                              Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. 192.178.18.1                                    0.0%    10    0.2   0.2   0.2   0.2   0.0
 2. 10.10.98.1                                      0.0%    10    0.5   0.5   0.4   0.5   0.0
 3. 192.168.10.1                                    0.0%    10    3.4   4.3   2.1   8.1   2.0
 4. 192.168.30.3                                    0.0%     9    2.8   5.6   1.6  23.7   6.9

Understanding the Columns

ColumnDescription
HostIP address or hostname of each hop
Loss%Percentage of packet loss at each hop
SntNumber of packets sent
LastLatency (roundtrip time) of the last packet sent
AvgAverage latency (roundtrip time) of all packets
BestBest (shortest) latency of all packets sent
WrstWorst (longest) latency of all packets sent
StDevStandard deviation of the latencies of all packets sent

Interpreting the Results

Hop 1: 192.178.18.1

  • Loss: 0% (perfect, no packet loss)
  • Average latency: 0.2ms (very fast, local network)
  • Very consistent (StDev = 0.0)

Hop 4: 192.168.30.3 (destination)

  • Loss: 0% (all packets reached destination)
  • Average latency: 5.6ms
  • More variable (StDev = 6.9ms, Wrst = 23.7ms indicates occasional delays)

Analogy: mtr is like a live traffic report for your data. While traceroute gives you a single snapshot of the route, mtr continuously monitors the route like a traffic camera, showing you real-time statistics about packet loss and delays at each hop. It's particularly useful for identifying network problems - if you see high packet loss or latency at a specific hop, you know where the problem is.

Use Cases:

  • Identifying network bottlenecks
  • Detecting intermittent connection issues
  • Monitoring network quality in real-time
  • Troubleshooting latency problems

Assignments

Assignment 1: Find IP Addresses

Objective: Find the IP address of the following domain names and those you are interested in.

Domain NameIP Address
www.google.com

Instructions:

  1. Use the host or nslookup command to find IP addresses
  2. Fill in the table with your findings
  3. Add additional domain names you're interested in
  4. Show your completed table to a TA for signature

Example Command:

$ host www.google.com

or

$ nslookup www.google.com

TA's Signature: ________________________


Assignment 2: Capture Packets Using Traceroute

Objective: Use Wireshark to verify and understand the mechanism of the traceroute command (how packets flow and discover the gateways).

Network Topology

The network setup for this assignment:

pc1 (192.178.18.1/24)
    |
    eth0
    |
router1 (eth1: 10.10.98.2/24)
    |
    eth0 (10.10.98.1/24)
    |
router2 (eth1: 192.168.10.2/24)
    |
    eth0 (192.168.10.1/24)
    |
router3 (eth1: ?)

Important: Make sure the static route configuration is correct in PC1.

Static routing configuration should include:

0.0.0.0 192.178.18.1
10.0.0.0/8

Step-by-Step Instructions

Step 0: Setup Network

  • Use IMUNES to create the network as shown in the topology diagram above
  • Verify all connections are properly configured
  • Ensure static routes are correct in PC1

Step 1: Start Wireshark

  • Open Wireshark on PC1
  • Select the appropriate network interface (eth0)
  • Start capturing packets

Step 2: Run Traceroute Command

$ traceroute -n 192.168.10.1

Expected Output:

traceroute to 192.168.10.1 (192.168.10.1), 30 hops max, 60 byte packets
 1  192.178.18.1  0.130 ms  0.109 ms  0.101 ms
 2  10.10.98.1  0.495 ms  0.504 ms  0.495 ms
 3  192.168.10.1  2.019 ms  2.711 ms  2.735 ms
student@netlab09:~$ _

Questions to Answer (Show to TA)

Hint: The details in this website might help you find the answer: Working of Traceroute using Wireshark

2.1) Discovery of Gateway 192.178.18.1

  • Which packets are used to discover the gateway 192.178.18.1?
  • Identify the corresponding ICMP packet sent back from this gateway

What to look for in Wireshark:

  • Look for UDP packets with TTL = 1
  • Find the corresponding ICMP "Time-to-live exceeded" messages

2.2) Discovery of Gateway 10.10.98.1

  • Which packets are used to discover the gateway 10.10.98.1?
  • Identify the corresponding ICMP packet sent back from this gateway

What to look for in Wireshark:

  • Look for UDP packets with TTL = 2
  • Find the corresponding ICMP "Time-to-live exceeded" messages

2.3) Discovery of Gateway 192.168.10.1

  • Which packets are used to discover the gateway 192.168.10.1?
  • Identify the corresponding ICMP packet sent back from this gateway

What to look for in Wireshark:

  • Look for UDP packets with TTL = 3
  • Find the corresponding ICMP messages (may be "Destination unreachable" since this is the final destination)

Understanding Traceroute Mechanism

How Traceroute Works with TTL:

  1. First Probe (TTL = 1):

    • Send UDP packet with TTL = 1
    • First router decrements TTL to 0
    • Router sends back ICMP "Time Exceeded" message
    • This reveals the first hop (192.178.18.1)
  2. Second Probe (TTL = 2):

    • Send UDP packet with TTL = 2
    • First router decrements to 1, forwards
    • Second router decrements to 0
    • Second router sends back ICMP "Time Exceeded"
    • This reveals the second hop (10.10.98.1)
  3. Third Probe (TTL = 3):

    • Send UDP packet with TTL = 3
    • Reaches destination (192.168.10.1)
    • Destination sends ICMP "Port Unreachable" or similar
    • This reveals the final destination

Analogy: TTL (Time To Live) is like a package with stamps. Each router removes one stamp. When a router removes the last stamp (TTL reaches 0), it sends a note back saying "Hey, I couldn't forward this because it ran out of stamps!" That's how traceroute discovers each router along the path.

TA's Signature: ________________________


Quiz Answer Sheet

Name and ID: _________________________________

Part 1: Lab Exercise Completion

When you complete all exercises, show your Lab Sheet to a TA to check in this box and sign the name.

☐ The student has finished all exercises.

TA's Signature: _____________________________

Part 2: Quiz Answers

Instruction: The quiz questions will be shown on the screen during the lab class. Write down your answers in the following table.

Question Types:

  • Questions 1 – 4: Multiple-choice questions (1 point each)
  • Questions 5 – 6: Short-answer questions (1 point each)
  • Questions 7 – 8: Explanation questions (2 points each)
QuestionAnswer
1A ☐ B ☐ C ☐ D ☐
2A ☐ B ☐ C ☐ D ☐
3A ☐ B ☐ C ☐ D ☐
4A ☐ B ☐ C ☐ D ☐
5
6
7
8

Total Score: _______


References

  • L. Limwiwatkul, ITS352 Lecture/Lab Note, Academic Year 2/2017
  • S. Gordon, Networking Lab Manual, 2015

Quick Reference Summary

DNS Lookup Commands Comparison

CommandPrimary UseOutput Detail
hostnameView/set local hostnameLocal system only
hostQuick DNS lookupSimple, concise
nslookupDetailed DNS queryShows DNS server used
digAdvanced DNS queriesMost detailed

Routing Commands Comparison

CommandPrimary UseReal-time?
routeView routing tableStatic snapshot
tracerouteShow path to destinationOne-time trace
mtrCombined ping + tracerouteYes, continuous
netstatNetwork statistics & connectionsStatic snapshot

Common Command Options

  • -n = Show IP addresses instead of hostnames (faster, no DNS lookup)
  • -s = Show statistics
  • -r = Show routing information

Port Numbers to Remember

  • DNS: Port 53
  • HTTP: Port 80
  • HTTPS: Port 443

Tips for Success

  1. Practice Commands: Try each command multiple times to understand the output
  2. Use -n Option: When you don't need hostname resolution (faster results)
  3. Understand TTL: Critical for understanding how traceroute works
  4. Read Wireshark Carefully: Look for patterns in packet types and TTL values
  5. Compare Tools: Use both host and nslookup to see different output formats

Study Tip: The best way to learn networking commands is to actually use them! Try tracing routes to different websites and comparing the results. Notice how some destinations require more hops than others, and observe how response times change based on geographic distance.


Common Issues and Solutions

Issue 1: Traceroute Shows Asterisks (**)

Cause: Firewall blocking UDP packets

Solution:

  • Try TCP mode: sudo traceroute -T destination
  • Or use mtr which might work better
  • Some networks block ICMP, so this is normal

Issue 2: DNS Lookup Fails

Cause: DNS server unreachable or domain doesn't exist

Solution:

  • Check your internet connection
  • Verify the domain name spelling
  • Try using a different DNS server
  • Use ping 8.8.8.8 to test general connectivity

Issue 3: Permission Denied

Cause: Some commands require root privileges

Solution:

  • Use sudo before the command
  • Example: sudo traceroute -T destination

Key Takeaways

  1. DNS is essential: Every domain name must be resolved to an IP address
  2. Routing tables direct traffic: Like a GPS for network packets
  3. Multiple hops are normal: Data rarely travels directly to its destination
  4. Firewalls can block diagnostic tools: This is a security feature, not a bug
  5. Latency varies by hop: Geographic distance and network congestion affect speed
  6. Real-time monitoring matters: Tools like mtr help identify intermittent issues

Final Thought: Networking is like a highway system for data. Understanding these tools helps you diagnose traffic jams (congestion), find alternative routes (routing), and understand why sometimes your data takes the scenic route!