Network debugging is the area where every utility has the same job and a slightly different syntax. netstat was deprecated and replaced by ss. dig, host, nslookup overlap. The route command on macOS isn't the route command on Linux. Asking by what you want, not what tool you remember, sidesteps the whole problem.
1. Listening ports
clai
$ clai show all listening TCP ports with the process name→ ss -ltnpState Recv-Q Local Address:Port ProcessLISTEN 0 0.0.0.0:22 users:(("sshd",pid=812))LISTEN 0 127.0.0.1:5432 users:(("postgres",pid=1234))
2. Established connections to a service
clai
$ clai who is connected to my postgres→ ss -tnp 'sport = :5432'ESTAB 10.0.1.12:54322 10.0.1.50:5432 users:(("postgres",pid=1234))
3. Why DNS feels slow
clai
$ clai trace why DNS for example.com resolves slowly→ dig +trace +stats example.com;; Query time: 312 msec;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
The +stats is the half nobody types. It's the difference between I know it's slow and I know which hop is slow.
4. Path MTU check
clai
$ clai check the MTU to 8.8.8.8→ ping -M do -c 3 -s 1472 8.8.8.81480 bytes from 8.8.8.8: ttl=58 time=12.4 ms
-M do sets the don't-fragment bit. If 1472+8+20 = 1500 fails, your effective MTU is below the standard.
5. Routing table — readable
clai
$ clai show me the routing table in human-readable form→ ip -4 route showdefault via 10.0.0.1 dev eth0 proto dhcp src 10.0.1.1210.0.0.0/16 dev eth0 proto kernel scope link src 10.0.1.12
See also
- Kill the process on port — for when the listening port investigation tells you what to stop.
- Docker and Kubernetes one-liners — when the network problem is inside containers, not on the host.