Memory hook: Address, route, name, socket, policy.
Must remember
Diagnose in layers. ip -br address shows addresses; ip route/ip -6 route show routes; getent hosts NAME tests configured name resolution; ss -lntup identifies listening sockets. A successful ping does not prove a TCP service works.
NetworkManager connection profiles preserve settings. nmcli connection show lists profiles; nmcli device status shows devices. Know how to set IPv4/IPv6 addresses, prefix, gateway, DNS and automatic activation on the intended profile, then activate and verify it. A temporary ip address add is not a persistent profile. A hostname can be set with hostnamectl; /etc/hosts and DNS resolve names through configured lookup order.
firewalld assigns connections/interfaces to zones. Services bundle ports; explicit port rules name port and protocol. Runtime changes affect now; --permanent changes saved configuration and needs a reload to become runtime state. A reload can discard unsaved runtime rules. Check --get-active-zones, --list-all and both runtime/permanent settings for the correct zone.
SSH key authentication uses a private key on the client and a public key in the server account's authorized keys. Protect ownership and modes of the home directory, .ssh and authorized_keys; SELinux labels also matter. Validate daemon syntax with sshd -t before a controlled reload. Keep a recovery session when changing remote connectivity in a practice VM.
scp and sftp transfer data through SSH. Confirm source/destination syntax and preserve the correct owner and labels afterward. A running service, enabled boot unit, listening address, firewall rule and valid authentication are independent checks.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Persistent static addressing | Modify and activate the NetworkManager profile. |
| Port works until reboot | Check saved firewalld and service activation settings. |
| Host resolves but connection fails | Check routes, listener address, firewall and authentication. |
Traps
- Opening a firewall port does not make an application listen.
- A rule in the wrong zone may have no effect on the intended interface.
Active recall
1. What shows listening TCP sockets?
ss -lntp, with sufficient privilege for process details.
2. Does ip address add persist across reboot?
Not by itself; configure the managed connection profile.
3. Does --permanent immediately open a port?
No. It changes saved configuration; reload or make the matching runtime change.
4. Which SSH key belongs in authorized_keys?
The client’s public key, never its private key.
5. Why can a successful ping mislead?
ICMP reachability does not establish that a TCP service, policy or login is working.