netstat: Network Statistics Display

netstat (network statistics) is a command-line utility for displaying network connections (both incoming and outgoing), routing tables, interface statistics, masquerade connections, and multicast memberships. It’s a fundamental tool for network troubleshooting and monitoring on Unix-like operating systems.

Note: On modern Linux distributions, the ss (socket statistics) command is often recommended as a faster and more capable replacement for netstat, as netstat is part of the deprecated net-tools package. However, netstat is still widely available and understood.

1. Checking Listening Ports

This command shows all TCP and UDP ports that are currently in a listening state on your system, along with the process ID (PID) and program name associated with them.

sudo netstat -tulpn | grep LISTEN

Command Breakdown:

  • sudo: Often required to see process information (PID/Program name) for all connections.
  • -t: Displays TCP connections.
  • -u: Displays UDP connections.
  • -l: Shows only listening sockets.
  • -p: Displays the PID and program name for the socket.
  • -n: Shows numerical addresses instead of trying to determine host, port, or user names (faster).
  • | grep LISTEN: Filters the output to only show lines containing “LISTEN”, which indicates that a port is open and waiting for incoming connections.

2. Common netstat Usage Examples

List All Connections (TCP and UDP)

netstat -a
  • -a: Displays all sockets (both listening and non-listening).

List All TCP Connections

netstat -at

List All UDP Connections

netstat -au

Display Routing Table

netstat -r
  • -r: Displays the kernel IP routing table.

Display Interface Statistics

netstat -i
  • -i: Displays a table of all network interfaces and their statistics.

Show Connections for a Specific Program

You can use grep to filter connections by a known service or program name.

netstat -tulpn | grep ssh

3. ss (Socket Statistics) as an Alternative

Here are some equivalent ss commands:

Check Listening Ports with ss

sudo ss -tulpn | grep LISTEN

List All TCP Connections with ss

ss -tuna

ss offers more features, especially for detailed socket information, and is generally faster for large numbers of connections.