CompTIA Linux+ (XK0-006)TroubleshootingMedium
A client reports that a web application running on a Linux server is inaccessible, and they receive 'Connection refused' errors. The technician checks the web server service status, which shows it is running, but `ss -tlnp` does not list the web server's expected listening port. What is the most likely cause?
- AThe server's firewall is blocking the port.
- BThe client's network route to the server is incorrect.
- CDNS resolution for the web server's hostname is failing.
- DThe web server application is misconfigured to listen on a different port or interface.
Show answer & explanationAnswer & explanation
Correct answer: D. The web server application is misconfigured to listen on a different port or interface.
If the service is running but `ss -tlnp` doesn't show the expected listening port, it means the application itself is not binding to that port. This is a strong indicator of an application-level configuration error, where it's either configured to listen on a different port, a different interface, or failed to bind for another reason.
Why the other options are wrong
- A. If the firewall were blocking, `ss -tlnp` would still show the port as listening, but connections would be dropped from outside.
- B. An incorrect client network route would prevent any connection attempt, not specifically result in 'Connection refused' after reaching the server.
- C. DNS resolution issues would prevent the client from finding the server's IP, but wouldn't cause a 'Connection refused' if the server was listening.
ss -tlnp for listening ports
The `ss -tlnp` command lists all TCP (t) sockets in listening (l) state, showing their numerical (n) port numbers and the process (p) that opened them. It's crucial for verifying if a service is actually binding to its intended port.
- Shows TCP sockets only.
- Lists ports in a listening state.
- Displays the process ID and name associated with the listening port.
- Useful for diagnosing 'Connection Refused' errors when a service should be listening.
Memory trick: No socket, no service, no connection.