A situation
Your laptop feels slow, and the network light keeps flashing. Which programs are using the network, and what are they connected to? Or a new web server does not answer: is it even listening on port 443? You answer both questions the same way: list the connections on the computer. Every operating system has a built-in tool for this.
What it is
netstat (network statistics) works on Windows, macOS and older Linux. ss (socket statistics) is its faster replacement on modern Linux. Both print one line per socket, showing many of the things you learned in this course:
- the protocol, TCP or UDP;
- the local address and port, and the remote (foreign or peer) address and port;
- for TCP, the connection state;
- optionally, the program that owns the socket.
- 1. Open connection: the browser is connected to 203.0.113.10 on port 443.
- 2. Waiting for an answer: a SYN went out, but no SYN-ACK has come back yet.
- 3. Listening port: a service on the laptop is waiting for other devices to connect to it.
Windows: netstat
Open Command Prompt and run netstat -ano. -a shows all sockets, including listening ones; -n shows addresses and ports as numbers instead of names (faster and clearer); -o adds the process ID (PID) of the program that owns each socket.
C:\> netstat -ano Active Connections Proto Local Address Foreign Address State PID TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1012 TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 TCP 192.168.1.20:52000 203.0.113.10:443 ESTABLISHED 8840 TCP 192.168.1.20:52001 203.0.113.10:443 ESTABLISHED 8840 TCP 192.168.1.20:52004 198.51.100.25:443 TIME_WAIT 0 TCP 192.168.1.20:52010 198.51.100.77:443 SYN_SENT 8840 UDP 0.0.0.0:5353 *:* 2480 UDP 192.168.1.20:137 *:* 4
0.0.0.0:135 in LISTENING means “waiting on port 135 on every IPv4 address of this PC”. The two ESTABLISHED lines are two browser connections (PID 8840) to the same server, with different source ports. SYN_SENT is a connection still waiting for a SYN-ACK. The UDP lines have no state, because UDP has no connections.tasklist /FI "PID eq 8840"Shows which program has process ID 8840 (here, the browser).
Linux: ss
On Linux, ss -tuna does the same job: -t shows TCP, -u UDP, -n numbers instead of names, and -a all sockets.
$ ss -tuna Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port udp UNCONN 0 0 0.0.0.0:5353 0.0.0.0:* udp ESTAB 0 0 192.168.1.30:41822 192.168.1.1:53 tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* tcp ESTAB 0 0 192.168.1.30:22 192.168.1.20:52114 tcp ESTAB 0 0 192.168.1.30:48210 203.0.113.10:443 tcp TIME-WAIT 0 0 192.168.1.30:48196 203.0.113.10:443
sudo ss -tlnpShows only listening TCP sockets (-l), with the owning program and PID (-p). It needs root (sudo) rights to show programs owned by other users.
Reading the states
| State you see | What it tells you |
|---|---|
LISTENING / LISTEN | A service is waiting for connections on that port |
ESTABLISHED / ESTAB | An open connection that can carry data |
SYN_SENT | Waiting for a SYN-ACK; if it stays, a firewall may be dropping the SYN |
TIME_WAIT | Recently closed, and this side closed first; clears by itself |
CLOSE_WAIT | The other side closed; a local program has not closed its side yet |
Why it works this way
The operating system keeps a table of every socket, because it needs that table to pass each incoming segment to the right program. netstat and ss simply print the table, so what you see is exactly what the computer uses. If a TCP port is not in LISTEN, a SYN sent to it normally gets an RST, unless a firewall on the computer drops the SYN first.
Check yourself
You set up a new web server, and netstat shows TCP 0.0.0.0:443 in LISTENING. What does this mean?
Your PC tries to reach a server, and netstat shows the connection stuck in SYN_SENT for a long time. What is the most likely reason?
In your netstat output, the TCP lines show states such as LISTENING and ESTABLISHED, but the UDP lines show none. Why?