Linux ss Command: Inspect Open Ports and Sockets
ss shows the listening ports and connection status of TCP and UDP sockets. It is used to check which address a service is listening on and whether the connection has actually been established.
What is the ss command?
If run without options, it generally displays connected non-listening sockets. To check server ports, include listening sockets with -l, and limit the protocol with -t or -u. -p shows the connection process information, but you may need permissions for information from other users.
Basic syntax
ss [option] [filter]
The installed implementation and options may vary depending on the distribution. Check the current system's description with man ss.
Examples
TCP listening ports
Check the service's listening status with numeric addresses and ports.
ss -ltn
TCP and UDP listening ports and processes
Check which process is using the port. Use sudo if necessary.
sudo ss -ltnup
Connections of a specific port
Filters connections corresponding to an example port 22.
ss -tn '( sport = :22 or dport = :22 )'
How should we read a listening socket?
ss -ltn shows listening sockets (-l) for TCP (-t) with numeric addresses and ports (-n).
ss -ltn
Part of example output (addresses and queue sizes vary depending on the environment):
State Recv-Q Send-Q Local Address:Port Peer Address:Port LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
0.0.0.0:22 means it is listening on port 22 of all local IPv4 addresses. The fact that a socket is listening alone does not allow you to conclude that it can be accessed from a firewall or external network. Process names can be seen with -p, but some may be hidden depending on permissions.
A service bound only to 127.0.0.1:port may be reachable locally but not through an external interface. Binding to 0.0.0.0 still does not bypass a firewall or security group. When investigating a port conflict, use ss -ltnp to identify the owning process if your permissions allow it.
Main Options and Format
| Options/Format | Description |
|---|---|
-l |
Displays listening sockets. |
-t / -u |
Selects TCP or UDP sockets. |
-n |
Displays addresses and ports in numeric form. |
-p |
Displays process information using sockets. |
-a |
Includes both listening and non-listening sockets. |
-s |
Displays socket summary by protocol. |
Precautions when using
If the service is listening only on 127.0.0.1, external connections are not possible, and listening on 0.0.0.0 does not necessarily mean that the firewall is also open. UDP does not have a connection state like TCP. If the process information for -p is empty, check the permissions.
Frequently Asked Questions
You can see the port with ss, but why can't you connect from outside?
You need to separately check whether the receiving address is a loopback, and whether the firewall, routing, or cloud security rules allow it.
Official Documentation
You can check the exact behavior of the options and the differences between implementations in the official ss documentation.









