Module 8 · Archives, compression and the network
netstat, routes and ports
Read the routing table that decides where every packet goes, add a route, and use netstat to see which ports are listening and which connections are open.
What you will learn
- Read the routing table with `ip route`, `route -n` and `netstat -rn`, and find the default gateway.
- Add and delete a route.
- Explain ports and list listening and established sockets with netstat.
Routes: where does this packet go?
For every packet it sends, the kernel looks up the destination in the routing table and picks the most specific matching line. Two kinds of line matter. A connected route says *this network is directly on eth0, deliver straight to the host*. The default route (0.0.0.0/0, written default) catches everything else and says *hand it to this gateway*, the router that knows the way onwards. A machine without a default route can only talk to its own subnet.
~% ip route
default via 192.168.86.1 dev eth0
192.168.86.0/24 dev eth0 scope link src 192.168.86.100
~% route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.86.1 0.0.0.0 UG 0 0 0 eth0
192.168.86.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
Three commands, one table. ip route is the modern view. route -n and netstat -rn print the classic table, where flag U means the route is up and G that it goes through a gateway; -n keeps addresses numeric instead of trying to turn them into names, which is faster and avoids hanging when DNS is broken. With the network off in this VM the table is empty until some interface has an address, which is why the exercises add one.
~% ip route add 10.9.0.0/24 dev eth0 # a network reachable on eth0
~% ip route add default via 192.168.86.1 # the default gateway
~% ip route del 10.9.0.0/24
~% route add -net 10.9.0.0 netmask 255.255.255.0 dev eth0 # classic syntax
Ports and sockets
An IP address finds the machine; a port (a number from 1 to 65535) finds the program on it. Servers listen on well-known ports: 22 for SSH, 53 for DNS, 80 for HTTP, 443 for HTTPS. A client connects from a random high port, and the pair of address:port ends is a connection. TCP connections have states, such as LISTEN and ESTABLISHED; UDP has none.
netstat lists them. -t selects TCP and -u UDP, -l shows only listening sockets, -a all of them, and -n again keeps numbers. The two questions you will ask most are *what is listening on this machine?* (netstat -tln) and *who is connected right now?* (netstat -tn). On full distributions -p adds the program name, and ss -tlnp is the modern replacement; this BusyBox build has neither, but fuser and /proc/net/tcp fill the gap.
~% printf '8080 stream tcp nowait root /bin/cat cat\n' > /etc/inetd.conf
~% inetd
~% netstat -tln
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:8080 0.0.0.0:* LISTEN
~% netstat -tn # during a download
tcp 0 0 192.168.86.100:44634 192.168.87.1:80 ESTABLISHED
Commands in this lesson
| Command | What it does |
|---|---|
ip route | Show the routing table (modern). |
route -n | Classic routing table, numeric (also netstat -rn). |
ip route add NET/24 dev eth0 | Add a route (del removes it). |
ip route add default via GW | Set the default gateway. |
netstat -tln | Listening TCP ports, numeric. |
netstat -uln | Listening UDP ports. |
netstat -tn | Established TCP connections. |
Quiz
What does the line `default via 192.168.86.1 dev eth0` mean?
- Packets for any address not matched by another route go to 192.168.86.1
- 192.168.86.1 is this machine's address
- Only traffic to 192.168.86.1 uses eth0
- DNS lives at 192.168.86.1
In `route -n`, what does the flag G mean?
- Global address
- The route goes through a gateway
- Group route
- Generated by DHCP
Which command shows the TCP ports this machine is listening on, without name lookups?
- netstat -rn
- netstat -tln
- netstat -tn
- ip route
Which port does a web server normally listen on for plain HTTP?
- 22
- 53
- 80
- 443
A service shows `127.0.0.1:5432 LISTEN`. Who can connect to it?
- Anyone on the internet
- Only programs on the same machine
- Only the gateway
- Nobody, it is closed
Practice
The setup gave eth0 the extra address 10.0.0.5/24. Save the routing table in numeric form into `/root/lab/l79/routes.txt` (any of the three commands from the lesson is fine).
Add a route so that the network `10.9.0.0/24` is reached directly through `eth0`.
`/etc/inetd.conf` already defines a small service on TCP port 8080. Start `inetd`, then save the list of listening TCP sockets (numeric) into `/root/lab/l79/listen.txt`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.