Linux ss Command: Inspect Open Ports and Sockets

ss shows the listening ports and connection status of TCP and UDP sockets. It is used to check which address a service is listening on and whether the connection has actually been established.

What is the ss command?

If run without options, it generally displays connected non-listening sockets. To check server ports, include listening sockets with -l, and limit the protocol with -t or -u. -p shows the connection process information, but you may need permissions for information from other users.

Basic syntax

ss [option] [filter]

The installed implementation and options may vary depending on the distribution. Check the current system's description with man ss.

Examples

TCP listening ports

Check the service's listening status with numeric addresses and ports.

ss -ltn

TCP and UDP listening ports and processes

Check which process is using the port. Use sudo if necessary.

sudo ss -ltnup

Connections of a specific port

Filters connections corresponding to an example port 22.

ss -tn '( sport = :22 or dport = :22 )'

How should we read a listening socket?

ss -ltn shows listening sockets (-l) for TCP (-t) with numeric addresses and ports (-n).

ss -ltn

Part of example output (addresses and queue sizes vary depending on the environment):

State  Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0      128    0.0.0.0:22         0.0.0.0:*

0.0.0.0:22 means it is listening on port 22 of all local IPv4 addresses. The fact that a socket is listening alone does not allow you to conclude that it can be accessed from a firewall or external network. Process names can be seen with -p, but some may be hidden depending on permissions.

A service bound only to 127.0.0.1:port may be reachable locally but not through an external interface. Binding to 0.0.0.0 still does not bypass a firewall or security group. When investigating a port conflict, use ss -ltnp to identify the owning process if your permissions allow it.

Main Options and Format

Options/Format Description
-l Displays listening sockets.
-t / -u Selects TCP or UDP sockets.
-n Displays addresses and ports in numeric form.
-p Displays process information using sockets.
-a Includes both listening and non-listening sockets.
-s Displays socket summary by protocol.

Precautions when using

If the service is listening only on 127.0.0.1, external connections are not possible, and listening on 0.0.0.0 does not necessarily mean that the firewall is also open. UDP does not have a connection state like TCP. If the process information for -p is empty, check the permissions.

Frequently Asked Questions

You can see the port with ss, but why can't you connect from outside?

You need to separately check whether the receiving address is a loopback, and whether the firewall, routing, or cloud security rules allow it.

Official Documentation

You can check the exact behavior of the options and the differences between implementations in the official ss documentation.

More in This Category
Linux tail Command: View the End of a File and Follow Logs

Linux tail Command: View the End of a File and Follow Logs

Learn how to use the Linux tail command to view the last lines of a file and follow log updates in real time, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux history Command: Review and Reuse Shell Command History

Linux history Command: Review and Reuse Shell Command History

Learn how to use the Linux history command to review, search, reuse, and manage shell command history, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux traceroute Command: Trace Routers on the Way to a Host

Linux traceroute Command: Trace Routers on the Way to a Host

Learn how to trace Routers on the Way to a Host with the Linux traceroute command, including practical examples, key options, and important precautions.

Linux Tutorial / Navigate Directories with pwd, ls, cd, and tree

Linux Tutorial / Navigate Directories with pwd, ls, cd, and tree

Use pwd, ls, cd, and tree to find your current location, inspect directories, navigate paths, and check where each command takes you.

Linux apt-get Command: Run APT Package Operations in Scripts

Linux apt-get Command: Run APT Package Operations in Scripts

Learn how to run APT Package Operations in Scripts with the Linux apt-get command, including practical examples, key options, and important precautions.

Linux Directory Structure Explained: Purpose of Major Directories

Linux Directory Structure Explained: Purpose of Major Directories

Understand the purpose of major Linux directories such as /etc, /var, /usr, /home, /proc, and /sys, and learn where common system files belong.

Linux systemctl Command: Manage systemd Services

Linux systemctl Command: Manage systemd Services

Learn how to manage systemd Services with the Linux systemctl command, including practical examples, key options, and important precautions.

Linux rmdir Command: Remove Empty Directories

Linux rmdir Command: Remove Empty Directories

Learn how to remove empty directories with Linux rmdir, delete empty parent paths, diagnose failures, and understand when rm -r is different.

Linux Tutorial / File System Basics: Paths and Key Directories

Linux Tutorial / File System Basics: Paths and Key Directories

Understand the Linux directory tree, read absolute and relative paths, and learn what common directories such as /home, /etc, and /var are used for.

Linux nohup Command: Keep a Command Running After Logout

Linux nohup Command: Keep a Command Running After Logout

Learn how to use the Linux nohup command to keep a command running after the terminal closes or the user logs out, with essential options, practical examples, output interpretation, and common troubleshooting tips.