Andrew Mercer
on this page

What it is

ss (from iproute2) dumps socket information straight from the kernel and replaces netstat, which is deprecated and no longer installed by default on most distributions. It is faster on busy hosts and can filter by state, port, and address.

Which services are listening?

sudo ss -tulpn
Flag Meaning
-t / -u TCP / UDP
-l listening sockets only
-p owning process (needs root to see other users' processes)
-n numeric ports and addresses, no name lookups
-a all sockets, listening and connected
-4 / -6 one address family

sudo ss -antlp (TCP only, all states, listening) is a typical variant. Example output:

State   Recv-Q  Send-Q  Local Address:Port  Peer Address:Port  Process
LISTEN  0       511     0.0.0.0:80          0.0.0.0:*          users:(("nginx",pid=2019,fd=6))
LISTEN  0       80      127.0.0.1:3306      0.0.0.0:*          users:(("mysqld",pid=1484,fd=21))

127.0.0.1 means local only; 0.0.0.0 or [::] means every interface. Check this when a service is "running" but unreachable from other hosts.

Who is using port 80?

sudo ss -ltnp 'sport = :80'

Filtering connections

ss -tn state established '( dport = :443 or sport = :443 )'
ss -tn dst 203.0.113.0/24
ss -s                                   # summary counts by state
ss -tni                                 # per-connection TCP internals (rtt, cwnd, retrans)

A TIME-WAIT pile-up and a large Recv-Q on a listener mean different things: Recv-Q on a LISTEN socket is the accept backlog. If it is at the limit, the application is not accepting connections fast enough.

Migrating from netstat

netstat ss
netstat -tulpn ss -tulpn
netstat --tcp --listening --program ss -tlp
netstat -lntp \| grep 80 ss -lntp 'sport = :80'
netstat -s ss -s (summary) or nstat (protocol counters)
netstat -i ip -s link
netstat -rn ip route
netstat -an ss -an