data:image/s3,"s3://crabby-images/d8217/d821775fdb85b865fbe45217e86021d0e843fe4c" alt=""
Linux tools for network administrators
My initial reaction to Linux was that I did not fully understand its range of tools. At that time, I was the technology director for a small K-12 public school district with limited resources but a growing number of classrooms, learning labs, and administrative offices. I came from a social science background, and although I was willing to learn, I was acutely aware of how little I knew. It did not take too long to understand what powerful tools enabled me to discover our network and learn the intricacies of TCP/IP.
Here’s a list of ten tools that became a significant part of my repertoire. I used them to teach others about network computing and the power of Linux.
The ping command is one of the most frequently used by sysadmins. It utilizes ICMP packets to verify whether two machines are connected.
$ ping 192.168.86.1
I learned that I could also ping a domain.
$ ping donwatkins.info
The traceroute command displays the route from your current machine to the remote server/system, showing each hop.
$ traceroute donwatkins.info
Traceroute can identify the network path, detect latency, locate network issues, and visualize network topology. Here is the result of the traceroute command:
1 192.168.1.1 1.114ms 0.234ms 0.125ms
2 67.252.48.1 21.260ms 12.357ms 20.123ms
3 24.58.217.101 29.425ms 32.921ms 32.608ms
4 24.58.38.176 10.866ms 11.450ms 10.017ms
5 24.58.32.62 25.848ms 25.377ms 15.594ms
6 66.109.6.2 24.275ms * 30.399ms
The mtr command is a combination of ping and traceroute. It is used to track packet loss. MTR is a versatile and dynamic tool that provides sysadmins with valuable insights into network performance and helps them identify and resolve issues efficiently.
$ mtr donwatkins.info
You can use the ifconfig tool to find your IP address. It provides TCP/IP information for all your network addresses, including the loopback address.
$ ifconfig
The netstat (network statistics) command-line tool provides detailed information about network connections, routing tables, interface statistics, masquerade connections, and multicast memberships on a system. If you want to see your system’s network activity, consider using the following command.
$ netstat -a
If you are looking for DNS information, dig is the tool you should use. It is a flexible tool for interrogating DNS name servers. It performs DNS lookups and displays the answers returned from the name server(s) that were queried.
$ dig donwatkins.info
One of my favorite tools for discovering what traffic is coming across my network is tcpdump. It is a powerful command-line packet analyzer used for network traffic monitoring and analysis. It captures and displays the packets being transmitted or received over your network. You need administrative privileges to run the command.
$ sudo tcpdump
The whois command queries databases that store registered domain names and related information. This command is useful if you need information about a specific domain, such as its registrar.
$ whois donwatkins.info
If you are looking for a powerful and versatile tool for network discovery and security auditing, then Nmap is for you. It can discover devices on a network, identify their IP addresses, and collect information about them, creating a detailed network inventory. Be sure to check the Nmap project website for excellent documentation on its use. I use nmap to scan my router to see which ports are open.
$ nmap 192.168.1.1
One of my favorite network monitoring tools is ntopng. It is a web-based application for monitoring network traffic released under the GPLv3 license. Ntopng is the modern version of the original tool, ntop, created by Luca Deri in 1998. It has been significantly improved in performance, usability, and features.
I am a graphical learner, and Etherape helped me visualize TCP/IP traffic across our network. It is easy to install on .deb or .rpm-based systems.
$ sudo apt install etherape
or
$ sudo dnf install etherape
Only an administrator can run Etherape, so you must add sudo to your command when executing it.
$ sudo etherape
Be sure to consult the documentation and Linux manual pages for all these commands to explore all the different options open to you as a Linux system administrator.