CHEAT SHEET
Networking cheat sheet
NetworkManager, the ip tools and firewalld. Set a static address, check ports, open a service.
nmcli
nmcli device status # devices and their statenmcli connection show # saved connectionsnmcli connection show lab # every setting of one connectionnmcli connection up lab # activate itnmcli connection down lab # deactivate itnmcli connection delete lab # remove itnmcli general hostname server1.example.com # set the hostname
Static IP and DHCP
nmcli connection add type ethernet ifname eth0 con-name lab \ ipv4.method manual ipv4.addresses 192.168.1.10/24 \ ipv4.gateway 192.168.1.1 ipv4.dns 192.168.1.1nmcli connection modify lab ipv4.dns "1.1.1.1 8.8.8.8" # change DNSnmcli connection modify lab +ipv4.addresses 192.168.1.11/24 # add a second addressnmcli connection modify lab ipv4.method auto ipv4.addresses "" ipv4.gateway "" # back to DHCPnmcli connection up lab # apply the change
ip, ss and tests
ip addr show # addressesip -br a # short, readable formip link set eth0 up # bring an interface upip route # routing tableip route get 8.8.8.8 # which route would be usedss -tulpn # listening ports with their processesping -c 3 host # reachabilitytracepath host # the path to a hostdig example.com # DNS lookup (bind-utils)curl -I https://example.com # HTTP headers onlync -zv host 22 # is a port open? (nmap-ncat)
Hostname and DNS files
hostnamectl # show the hostname and OShostnamectl set-hostname server1.example.com # set it permanentlycat /etc/resolv.conf # DNS servers in usecat /etc/hosts # static name mappings
firewalld
firewall-cmd --state # is it running?firewall-cmd --get-default-zone # default zonefirewall-cmd --get-active-zones # zones in usefirewall-cmd --list-all # rules of the active zonefirewall-cmd --get-services # known service namesfirewall-cmd --add-service=http # runtime onlyfirewall-cmd --permanent --add-service=http # saved, active after a reloadfirewall-cmd --permanent --add-port=8080/tcp # open a portfirewall-cmd --permanent --remove-service=http # close a servicefirewall-cmd --reload # load the permanent rulesfirewall-cmd --runtime-to-permanent # save what is active now
Zones and rich rules
firewall-cmd --permanent --zone=internal --add-source=10.0.0.0/24 # a network into a zonefirewall-cmd --permanent --zone=public --change-interface=eth0 # an interface into a zonefirewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/24" service name="ssh" accept'
More cheat sheets
Questions
How do I set a static IP address with nmcli?
Use nmcli connection modify NAME ipv4.method manual ipv4.addresses 192.168.1.10/24 ipv4.gateway 192.168.1.1 ipv4.dns 192.168.1.1, then nmcli connection up NAME.
How do I open a port in firewalld permanently?
Run firewall-cmd --permanent --add-port=8080/tcp and then firewall-cmd --reload.
How do I list listening ports on Linux?
Use ss -tulpn. It shows TCP and UDP listeners with the process that owns each port.
What is the difference between runtime and permanent in firewalld?
Runtime rules apply immediately and are lost on reload or reboot. Permanent rules are saved but only become active after firewall-cmd --reload.