Linux ss Command: Inspect Open Ports and Sockets

ss shows the listening ports and connection status of TCP and UDP sockets. It is used to check which address a service is listening on and whether the connection has actually been established.

What is the ss command?

If run without options, it generally displays connected non-listening sockets. To check server ports, include listening sockets with -l, and limit the protocol with -t or -u. -p shows the connection process information, but you may need permissions for information from other users.

Basic syntax

ss [option] [filter]

The installed implementation and options may vary depending on the distribution. Check the current system's description with man ss.

Examples

TCP listening ports

Check the service's listening status with numeric addresses and ports.

ss -ltn

TCP and UDP listening ports and processes

Check which process is using the port. Use sudo if necessary.

sudo ss -ltnup

Connections of a specific port

Filters connections corresponding to an example port 22.

ss -tn '( sport = :22 or dport = :22 )'

How should we read a listening socket?

ss -ltn shows listening sockets (-l) for TCP (-t) with numeric addresses and ports (-n).

ss -ltn

Part of example output (addresses and queue sizes vary depending on the environment):

State  Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0      128    0.0.0.0:22         0.0.0.0:*

0.0.0.0:22 means it is listening on port 22 of all local IPv4 addresses. The fact that a socket is listening alone does not allow you to conclude that it can be accessed from a firewall or external network. Process names can be seen with -p, but some may be hidden depending on permissions.

A service bound only to 127.0.0.1:port may be reachable locally but not through an external interface. Binding to 0.0.0.0 still does not bypass a firewall or security group. When investigating a port conflict, use ss -ltnp to identify the owning process if your permissions allow it.

Main Options and Format

Options/Format Description
-l Displays listening sockets.
-t / -u Selects TCP or UDP sockets.
-n Displays addresses and ports in numeric form.
-p Displays process information using sockets.
-a Includes both listening and non-listening sockets.
-s Displays socket summary by protocol.

Precautions when using

If the service is listening only on 127.0.0.1, external connections are not possible, and listening on 0.0.0.0 does not necessarily mean that the firewall is also open. UDP does not have a connection state like TCP. If the process information for -p is empty, check the permissions.

Frequently Asked Questions

You can see the port with ss, but why can't you connect from outside?

You need to separately check whether the receiving address is a loopback, and whether the firewall, routing, or cloud security rules allow it.

Official Documentation

You can check the exact behavior of the options and the differences between implementations in the official ss documentation.

More in This Category
Linux stat Command: Display Detailed File Metadata

Linux stat Command: Display Detailed File Metadata

Learn how to use the Linux stat command to inspect file size, permissions, ownership, timestamps, inode, and filesystem metadata, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux host Command: Look Up DNS Names and Addresses

Linux host Command: Look Up DNS Names and Addresses

Learn how to look Up DNS Names and Addresses with the Linux host command, including practical examples, key options, and important precautions.

Linux pacman Command: Manage Packages on Arch Linux

Linux pacman Command: Manage Packages on Arch Linux

Learn how to manage Packages on Arch Linux with the Linux pacman command, including practical examples, key options, and important precautions.

Linux ss Command: Inspect Open Ports and Sockets

Linux ss Command: Inspect Open Ports and Sockets

Learn how to inspect Open Ports and Sockets with the Linux ss command, including practical examples, key options, and important precautions.

Linux lsmod Command: List Loaded Kernel Modules

Linux lsmod Command: List Loaded Kernel Modules

Learn how to list Loaded Kernel Modules with the Linux lsmod command, including practical examples, key options, and important precautions.

Linux nc Command: Test TCP and UDP Connections

Linux nc Command: Test TCP and UDP Connections

Learn how to test TCP and UDP Connections with the Linux nc command, including practical examples, key options, and important precautions.

Linux free Command: Check Memory and Swap Usage

Linux free Command: Check Memory and Swap Usage

Learn how to use the Linux free command to inspect available memory, used memory, cache, and swap usage, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux uptime Command: Check Uptime and Load Averages

Linux uptime Command: Check Uptime and Load Averages

Learn how to use the Linux uptime command to check how long the system has been running and interpret load averages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux tmux Command: Detach and Reattach Terminal Sessions

Linux tmux Command: Detach and Reattach Terminal Sessions

Learn how to detach and Reattach Terminal Sessions with the Linux tmux command, including practical examples, key options, and important precautions.

Linux less Command: Browse and Search Long Text Files

Linux less Command: Browse and Search Long Text Files

Learn how to browse long files with Linux less, move forward and backward, search text, follow growing logs, preserve colors, and exit the pager.