Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.2.3 (11 of 20 in this unit)44 of 84 in the Network Fundamentals course

Viewing connections on your computer

Use netstat and ss to see open ports, connection states and which program owns them.

Beginner · 6 min read

netstat (network statistics) and ss (socket statistics) are command-line tools that list a computer's sockets: the protocol, the local and remote addresses and ports, the TCP connection state and, optionally, the program that owns each socket. netstat runs on Windows, macOS and older Linux; ss is its modern Linux replacement.

In simple terms: These commands show what your computer is connected to right now and which ports are open and waiting, so you can see which program is talking to which server.

A situation

Your laptop feels slow, and the network light keeps flashing. Which programs are using the network, and what are they connected to? Or a new web server does not answer: is it even listening on port 443? You answer both questions the same way: list the connections on the computer. Every operating system has a built-in tool for this.

What it is

netstat (network statistics) works on Windows, macOS and older Linux. ss (socket statistics) is its faster replacement on modern Linux. Both print one line per socket, showing many of the things you learned in this course:

  • the protocol, TCP or UDP;
  • the local address and port, and the remote (foreign or peer) address and port;
  • for TCP, the connection state;
  • optionally, the program that owns the socket.
Your laptop192.168.1.20Home router192.168.1.1Web server203.0.113.10:443Another site198.51.100.77:443
  1. 1. Open connection: the browser is connected to 203.0.113.10 on port 443.
  2. 2. Waiting for an answer: a SYN went out, but no SYN-ACK has come back yet.
  3. 3. Listening port: a service on the laptop is waiting for other devices to connect to it.

Windows: netstat

Open Command Prompt and run netstat -ano. -a shows all sockets, including listening ones; -n shows addresses and ports as numbers instead of names (faster and clearer); -o adds the process ID (PID) of the program that owns each socket.

Example output, written for this lesson; your own list will be different
C:\> netstat -ano
Active Connections

  Proto  Local Address          Foreign Address        State           PID
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       1012
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    192.168.1.20:52000     203.0.113.10:443       ESTABLISHED     8840
  TCP    192.168.1.20:52001     203.0.113.10:443       ESTABLISHED     8840
  TCP    192.168.1.20:52004     198.51.100.25:443      TIME_WAIT       0
  TCP    192.168.1.20:52010     198.51.100.77:443      SYN_SENT        8840
  UDP    0.0.0.0:5353           *:*                                    2480
  UDP    192.168.1.20:137       *:*                                    4
What to look for: 0.0.0.0:135 in LISTENING means “waiting on port 135 on every IPv4 address of this PC”. The two ESTABLISHED lines are two browser connections (PID 8840) to the same server, with different source ports. SYN_SENT is a connection still waiting for a SYN-ACK. The UDP lines have no state, because UDP has no connections.
tasklist /FI "PID eq 8840"

Shows which program has process ID 8840 (here, the browser).

Linux: ss

On Linux, ss -tuna does the same job: -t shows TCP, -u UDP, -n numbers instead of names, and -a all sockets.

Example output, written for this lesson; your own list will be different
$ ss -tuna
Netid State      Recv-Q Send-Q    Local Address:Port      Peer Address:Port
udp   UNCONN     0      0               0.0.0.0:5353           0.0.0.0:*
udp   ESTAB      0      0          192.168.1.30:41822      192.168.1.1:53
tcp   LISTEN     0      128             0.0.0.0:22             0.0.0.0:*
tcp   ESTAB      0      0          192.168.1.30:22        192.168.1.20:52114
tcp   ESTAB      0      0          192.168.1.30:48210     203.0.113.10:443
tcp   TIME-WAIT  0      0          192.168.1.30:48196     203.0.113.10:443
What to look for: this Linux PC (192.168.1.30) runs an SSH server (LISTEN on port 22), and someone at 192.168.1.20 is logged in to it (the ESTAB line with local port 22). On connected sockets, Recv-Q and Send-Q show bytes waiting in buffers; numbers that stay high point to a slow application or a full window. (On a LISTEN socket, Send-Q shows the maximum queue of waiting connections instead, here 128.) For UDP, ss writes UNCONN or ESTAB only to show whether the program has fixed a single remote address. There was no handshake.
sudo ss -tlnp

Shows only listening TCP sockets (-l), with the owning program and PID (-p). It needs root (sudo) rights to show programs owned by other users.

Reading the states

State you seeWhat it tells you
LISTENING / LISTENA service is waiting for connections on that port
ESTABLISHED / ESTABAn open connection that can carry data
SYN_SENTWaiting for a SYN-ACK; if it stays, a firewall may be dropping the SYN
TIME_WAITRecently closed, and this side closed first; clears by itself
CLOSE_WAITThe other side closed; a local program has not closed its side yet

Why it works this way

The operating system keeps a table of every socket, because it needs that table to pass each incoming segment to the right program. netstat and ss simply print the table, so what you see is exactly what the computer uses. If a TCP port is not in LISTEN, a SYN sent to it normally gets an RST, unless a firewall on the computer drops the SYN first.

Check yourself

Predict · scenario 1

You set up a new web server, and netstat shows TCP 0.0.0.0:443 in LISTENING. What does this mean?

Predict · scenario 2

Your PC tries to reach a server, and netstat shows the connection stuck in SYN_SENT for a long time. What is the most likely reason?

Predict · scenario 3

In your netstat output, the TCP lines show states such as LISTENING and ESTABLISHED, but the UDP lines show none. Why?