The ss command displays socket statistics and network connection details.
It is a modern replacement for many netstat use cases and is useful for diagnosing listening ports, active sessions, and transport-level state.
Overview
Use ss when you need to:
- See which ports are listening
- Inspect active TCP/UDP connections
- Troubleshoot connection states (ESTABLISHED, TIME-WAIT, etc.)
- Correlate sockets with owning processes
- Filter socket views by protocol, state, and address
Syntax
ss [options] [filter]
Common forms:
# Show all sockets
ss -a
# Show listening TCP sockets with process info
ss -ltnp
# Show active TCP connections
ss -tn
Common Options
| Option | Purpose | Example |
|---|---|---|
-a |
Show all sockets (listening and non-listening) | ss -a |
-l |
Show listening sockets only | ss -l |
-t |
TCP sockets only | ss -t |
-u |
UDP sockets only | ss -u |
-n |
Do not resolve service/host names | ss -tn |
-p |
Show process using socket | ss -ltnp |
-e |
Extended socket information | ss -te |
-m |
Show socket memory usage | ss -tm |
-s |
Summary statistics | ss -s |
-4 |
IPv4 sockets only | ss -4ltn |
-6 |
IPv6 sockets only | ss -6ltn |
-H |
Omit header line | ss -Htn |
Useful Filters
ss supports filter expressions after options.
Examples:
# Sockets using destination port 443
ss -tn 'dport = :443'
# Listening sockets on local port 8080
ss -ltn 'sport = :8080'
# Established TCP sessions only
ss -tn state established
Common state filters:
state listeningstate establishedstate time-waitstate close-wait
Examples
# List listening TCP ports numerically
ss -ltn
# Show listening sockets with processes (requires privileges for full detail)
sudo ss -ltnp
# Show all UDP listeners
ss -lun
# Show connections to remote HTTPS endpoints
ss -tn 'dport = :443'
# Show summary counts by protocol/state
ss -s
# Inspect sockets for a specific local service port
ss -ltnp 'sport = :5432'
Troubleshooting Workflow
Check whether service is listening:
ss -ltnp 'sport = :8080'
Check if clients are connecting:
ss -tn 'dport = :8080'
Inspect problematic states:
ss -tn state time-wait
ss -tn state close-wait
Safe Usage Guidelines
- Use
-nto avoid DNS/service-name resolution delays. - Use
sudoonly when process mapping (-p) detail is needed. - Combine protocol and state filters to reduce noise.
- Capture baseline snapshots before and after configuration changes.
Troubleshooting
Process names are missing in output
Cause: Insufficient privileges for process association.
Fix:
sudo ss -ltnp
Output is hard to read due to name resolution
Cause: Host/service names are being resolved.
Fix:
ss -tn
Port appears open but service is unreachable
Possible causes:
- Service bound to localhost only
- Firewall/network policy blocking traffic
- Application-level failures after accept
Next checks:
- Inspect local bind address in
ss -ltnp - Verify firewall rules and service logs
Notes
ss is part of the iproute2 tooling family on Linux.
For scripting, use stable flags (-n, protocol selectors, and state filters) to keep output predictable.
For command details and implementation-specific behavior, run:
man ss
ss --help