A web server is useful only if a request from the other side of the world reaches the process that answers it. On the way, the request crosses independent gates: a cloud security group outside the machine, the host firewall inside the kernel, and a socket that must be listening on the right address and port. Each gate fails with its own symptom on the client, so knowing the gates turns "the site does not load" into a short diagnosis. The examples run on this chapter's Ubuntu 26.04 225 LTS machine, where Apache 129 already listens on port 80.
