πŸ§ͺ Linux Networking and Service Exposure Lab

πŸ“Œ Objective

This lab simulates real-world Linux networking issues and teaches how to troubleshoot:

  • Service availability
  • Port listening
  • Firewall behavior (UFW)
  • Binding (’localhost’ vs external access)
  • Network-layer debugging

βš™οΈ Environment

  • OS: Ubuntu (VM + Bridged Adapter)
  • Service: Nginx
  • Tools: ss, curl, ufw, systemctl
  • Host machine for external testing (Powershell)

🟒 Stage 1

Verify service:

systemctl status nginx

Expected outcome: Active (running)

Check listening ports:

ss - tuln | grep :80

Expected outcome: 0.0.0.0:80

Verify

Test locally:

curl 192.160.0.199

Curl

Test from host:

Test-NetConnection 192.168.0.199 -Port 80

External_Test


πŸ”΄ Stage 2 - Break the System

πŸ§ͺ Challenge 1 - Firewall Block

sudo ufw enable
sudo ufw deny 80

Firewall Block

Expected Outcome:

  • Local curl works

Curl_Test

  • External connection fails

Test_Failure_1

πŸ”₯ Debugging

  1. Confirm service is running:
systemctl status nginx
  1. Confirm port is listening:
ss -tuln | grep :80

Expected Outcome:

0.0.0.0:80

  1. Test local access:
curl http://localhost

Debug1

  1. Check firewall state:
sudo ufw status verbose

Debug2

🧠 Diagnosis

Service run locally but not externally -> firewall is blocking TCP traffic

πŸ›  Fix

sudo ufw allow 80/tcp

or

sudo ufw disable

Debug3

βœ… Verification

From host:

Test

🧠 Key lesson

  1. PING working does not mean service is reachable
  2. Firewall blocks TCP, not ICMP in many cases

πŸ§ͺ Challenge 2 - Bind to localhost only

Edit conf:

sudo nano /etc/nginx/sites-available/default

Change:

listen 127.0.0.1:80;
listen [::1]:80;

Bind

Restart:

sudo systemctl restart nginx

Expected outcome:

  • curl localhost works βœ”
  • curl IP fails ❌

Break2

  • Host access fails ❌

Test_Failure_1

πŸ”₯ Debugging

  1. Check service:
systemctl status nginx

Debug1

  1. Check listening interface:
ss -tuln | grep :80

Expected Outcome:

127.0.0.1:80

  1. Test localhost explicitly:
curl http://localhost
  1. Test network IP address:
curl 192.168.0.199

Debug2

  1. Confirm config source:
nginx -T | grep listen

Debug2

🧠 Diagnosis

Service is restricted to loopback interface -> not exposed to network

πŸ›  Fix

Edit config:

sudo nano /etc/nginx/sites-available/default

Fix

Restart:

sudo systemctl restart nginx

βœ… Verification

ss -tuln | grep :80
curl http://192.168.0.199

Fix2

🧠 Key lesson

Binding defines WHO can connect, not whether service runs


πŸ§ͺ Challenge 3 - Wrong Port

Edit config:

listen 8080;
listen [::]:8080;

Restart:

sudo systemctl restart nginx

Expected outcome:

  • Port 80 fails ❌
  • Port 8080 works βœ”

Ports Powershell_Ports

πŸ”₯ Debugging

  1. Check service status:
systemctl status nginx
  1. Check listening ports:
ss -tuln | grep LISTEN

Fix3

πŸ‘‰ Nginx is NOT listening on port 80

  1. Test discovered port locally:

Port Test

  1. Verify from host:

Port Test

  1. Confirm config:
nginx -T | grep 

Expected Outcome:

listen 8080;

Config Test

🧠 Diagnosis

Service is running on the wrong port -> client is connecting to the wrong port

πŸ›  Fix

Edit config:

sudo nano /etc/nginx/sites-available/default

listen 80 default_server;
listen [::]:80 default_server;

Restart:

sudo systemtctl restart nginx

βœ… Verification

ss -tuln | grep :80

Debug

Test-NetConnection 192.168.0.199 -Port 80

Test

🧠 Key lesson

Service may be fully healthy but unreachable due to port mismatch


πŸ”₯ Debugging hierarchy

  1. Service (running?)
  2. Port (listening?)
  3. Binding (where?)
  4. Firewall (blocked?)
  5. Network (reachable?)