Skip to content

Network Issues

The key to network troubleshooting is layered diagnosis, progressively narrowing the scope. This article follows the order from the physical layer to the application layer, introducing a systematic network troubleshooting approach.

Network troubleshooting should follow the OSI model from the bottom up:

  1. Physical / Link layer — Cables, NIC, link status
  2. Network layer — IP address, routing, gateway
  3. DNS — Name resolution
  4. Firewall — firewalld / iptables rules
  5. Transport / Application layer — Ports, service listening status

Principle: Do not skip lower layers and jump straight to higher layers. If the IP address is misconfigured, troubleshooting DNS is pointless.

View network interface status
$ ip link show

Look for state UP vs. state DOWN. If the interface is in DOWN state:

Bring up the network interface
$ sudo ip link set eth0 up
Check if the NIC driver is loaded
$ lspci | grep -i ethernet
$ lsmod | grep -i e1000 # Example: Intel NIC
Use ethtool to check link status
$ sudo ethtool eth0

Look for Link detected: yes in the output. If it shows no, there is a physical connection problem (cable, switch port, virtual network configuration, etc.).

View NIC statistics (errors and drops)
$ ip -s link show eth0

Watch the errors and dropped counters. A high count may indicate hardware issues or a duplex mismatch.

View IP addresses on all interfaces
$ ip addr show
View the routing table
$ ip route show

Confirm the following:

  • The interface has the correct IP address
  • The subnet mask is correct
  • A default route exists (default via x.x.x.x)
Test connectivity to the gateway
$ ping -c 3 $(ip route show default | awk '{print $3}')

If pinging the gateway fails, the problem is in the local network configuration or physical connection.

Using nmcli to Check and Configure Networking

Section titled “Using nmcli to Check and Configure Networking”
View all connection configurations
$ nmcli connection show
View detailed configuration of a specific connection
$ nmcli connection show "Wired connection 1"
View device status
$ nmcli device status
Reactivate a connection
$ sudo nmcli connection down "Wired connection 1" && sudo nmcli connection up "Wired connection 1"

DHCP failed to obtain an address:

Manually request a DHCP address
$ sudo nmcli connection modify "Wired connection 1" ipv4.method auto
$ sudo nmcli connection up "Wired connection 1"
View DHCP client logs
$ journalctl -u NetworkManager --since "5 minutes ago" | grep -i dhcp

Setting a static IP:

Configure a static IP address
$ sudo nmcli connection modify "Wired connection 1" \
ipv4.method manual \
ipv4.addresses "192.168.1.100/24" \
ipv4.gateway "192.168.1.1" \
ipv4.dns "8.8.8.8 8.8.4.4"
$ sudo nmcli connection up "Wired connection 1"

If the IP layer is working (you can ping IP addresses) but you cannot access domain names:

Check DNS configuration
$ cat /etc/resolv.conf
Test DNS resolution
$ dig google.com
Test using a specific DNS server
$ dig @8.8.8.8 google.com
Concise output
$ dig +short google.com
Test reverse DNS lookup
$ dig -x 8.8.8.8

resolv.conf being overwritten:

NetworkManager manages /etc/resolv.conf. If manual changes keep being overwritten:

Configure DNS servers via nmcli
$ sudo nmcli connection modify "Wired connection 1" ipv4.dns "8.8.8.8 114.114.114.114"
$ sudo nmcli connection up "Wired connection 1"

Slow DNS resolution:

Measure resolution latency
$ time dig google.com

If latency is high, the DNS server may be unreachable or responding slowly. Try a different DNS server:

Temporarily test other DNS servers
$ dig @114.114.114.114 google.com
$ dig @223.5.5.5 google.com

Local hosts file issues:

Check /etc/hosts for unusual entries
$ cat /etc/hosts
Check resolution order in nsswitch.conf
$ grep hosts /etc/nsswitch.conf

The normal configuration is typically: hosts: files dns myhostname

The firewall is one of the most common causes of network issues on EL systems. If a service is running but cannot be accessed externally, nine times out of ten it is the firewall.

Check firewalld status
$ sudo firewall-cmd --state
List all rules in the current zone
$ sudo firewall-cmd --list-all
List all allowed services
$ sudo firewall-cmd --list-services
List all allowed ports
$ sudo firewall-cmd --list-ports
Temporarily allow a port (resets after reboot)
$ sudo firewall-cmd --add-port=8080/tcp
Temporarily allow a service
$ sudo firewall-cmd --add-service=http
Permanently allow a port
$ sudo firewall-cmd --add-port=8080/tcp --permanent
$ sudo firewall-cmd --reload
Permanently allow a service
$ sudo firewall-cmd --add-service=http --permanent
$ sudo firewall-cmd --add-service=https --permanent
$ sudo firewall-cmd --reload
Temporarily enable firewalld logging for denied traffic
$ sudo firewall-cmd --set-log-denied=all
View rejected traffic
$ sudo journalctl -f | grep REJECT

After testing, disable logging:

Disable denied traffic logging
$ sudo firewall-cmd --set-log-denied=off

If you need to quickly determine whether the firewall is the issue:

Temporarily move the interface to the trusted zone (allow all traffic)
$ sudo firewall-cmd --zone=trusted --change-interface=eth0

Warning: This completely opens the interface. Use only for temporary testing and restore immediately afterward.

Restore the interface to the default zone
$ sudo firewall-cmd --zone=public --change-interface=eth0
View all listening TCP ports
$ sudo ss -tlnp
View all listening UDP ports
$ sudo ss -ulnp
Check if a specific port is listening
$ sudo ss -tlnp | grep :80

If the service is not listening on the expected port, check the service status:

Check the service status
$ systemctl status nginx
$ journalctl -u nginx -n 30 --no-pager
Test local HTTP service
$ curl -v http://localhost/
Test and show response headers
$ curl -I http://localhost/
Test a specific port
$ curl -v http://localhost:8080/
Install traceroute (if not present)
$ sudo dnf install -y traceroute
Trace the route to a destination
$ traceroute 8.8.8.8
Use TCP mode (better at penetrating firewalls)
$ sudo traceroute -T -p 80 example.com
Capture traffic on a specific interface and port
$ sudo tcpdump -i eth0 port 80 -nn -c 20
Save packet capture to a file for later analysis
$ sudo tcpdump -i eth0 port 443 -w /tmp/capture.pcap -c 100

Scenario 1: Server is Pingable but HTTP is Not Working

Section titled “Scenario 1: Server is Pingable but HTTP is Not Working”

Troubleshooting order:

  1. Confirm the web service is running: systemctl status nginx
  2. Confirm the service is listening on the correct port: ss -tlnp | grep :80
  3. Confirm local access works: curl http://localhost/
  4. Check the firewall: firewall-cmd --list-all
  5. Check SELinux: ausearch -m avc -ts recent

Scenario 2: DNS Resolves but Connection Times Out

Section titled “Scenario 2: DNS Resolves but Connection Times Out”
Confirm whether the target port is reachable
$ timeout 5 bash -c 'echo > /dev/tcp/TARGET_IP/TARGET_PORT' && echo "Port reachable" || echo "Port unreachable"

Possible causes:

  • Remote firewall is blocking traffic
  • Routing issue (use traceroute to diagnose)
  • ISP or intermediate network device blocking

Scenario 3: NetworkManager Connection Keeps Disconnecting and Reconnecting

Section titled “Scenario 3: NetworkManager Connection Keeps Disconnecting and Reconnecting”
View NetworkManager logs
$ journalctl -u NetworkManager --since "30 minutes ago" | grep -E '(connect|disconnect|fail)'
Check physical status changes of the network interface
$ dmesg | grep -i 'link'

Possible causes:

  • Loose cable connection
  • NIC driver issue
  • DHCP lease conflict

Scenario 4: Network Configuration Lost After Migration

Section titled “Scenario 4: Network Configuration Lost After Migration”

After migrating from CentOS, network interface names or configuration files may change:

Check connection configuration files
$ ls /etc/NetworkManager/system-connections/
$ ls /etc/sysconfig/network-scripts/ifcfg-* 2>/dev/null
Recreate the connection
$ sudo nmcli connection add type ethernet con-name "Primary" ifname eth0
$ sudo nmcli connection modify "Primary" ipv4.method auto
$ sudo nmcli connection up "Primary"
TargetCommand
View interface statusip link show
View IP addressesip addr show
View routing tableip route show
Test connectivityping -c 3 target
DNS resolutiondig domain
View listening portsss -tlnp
Trace routetraceroute target
Firewall rulesfirewall-cmd --list-all
View connectionsnmcli connection show
Packet capturetcpdump -i interface port port-number
HTTP testcurl -v URL
NetworkManager logsjournalctl -u NetworkManager