CompTIA Linux+ (XK0-006)TroubleshootingMedium
A system administrator notices that a newly deployed web server is unreachable from the internet, although it can ping other internal servers. The web server's firewall configuration was recently updated. Which command should the administrator use to verify if the web server is listening on the correct port and if the firewall is blocking incoming connections to that port?
- A`journalctl -xe` to check for firewall-related errors.
- B`ss -tlnp` to list listening TCP sockets and associated processes.
- C`ip addr show` to check the server's IP address.
- D`cat /etc/hosts` to verify local hostname resolution.
Show answer & explanationAnswer & explanation
Correct answer: B. `ss -tlnp` to list listening TCP sockets and associated processes.
The `ss -tlnp` command displays all listening TCP sockets (`-tln`) along with the process (`-p`) that opened them. This immediately shows if the web server process is correctly binding to and listening on its designated port, and if it's not, or if it is but still unreachable, it points to a firewall or routing issue.
Why the other options are wrong
- A. `journalctl -xe` is useful for general system logs and errors, but `ss` directly confirms listening ports, which is a more immediate step for network connectivity issues.
- C. `ip addr show` confirms the server's IP, but doesn't show listening services or firewall status.
- D. `cat /etc/hosts` is for local hostname resolution and unrelated to external network reachability or listening ports.
ss -tlnp
The `ss -tlnp` command lists all listening TCP sockets (`-t`, `-l`) in numerical format (`-n`) and shows the process (`-p`) associated with each socket. It's vital for network troubleshooting to confirm services are listening on expected ports.
- Displays listening TCP sockets.
- Shows associated process IDs and names.
- Useful for verifying network service availability.
Memory trick: SS tells if the Server is Standing and Speaking.