Home / Alt manpages / netstat(8)

  • netstat(8)
  • Admin command
  • linux

Read Listening Sockets and Routes with netstat

You will use netstat to answer the practical networking questions that usually matter first: what is listening, which addresses are exposed, which process owns a socket, what route the kernel will use, and whether an interface is dropping packets. The examples match net-tools 2.10, installed here as package version 2.10-0.1ubuntu4.4.

Allow about 15 minutes. You need a shell and the net-tools package. These commands only read kernel networking information. They do not open ports, change routes, restart services or alter firewall rules.

1. Check the installed command

Confirm which binary will run and record its version:

$ command -v netstat
/usr/bin/netstat
$ netstat --version
net-tools 2.10

The output may include build features after the version line. That is normal. The command is old and the manpage calls it mostly obsolete, recommending ss for sockets, ip route for routes and ip -s link for interface statistics. It remains useful when you need its familiar output or a script already depends on it.

Checkpoint

If the command is missing, install the distribution package through your normal system administration process. Do not copy a binary from an unrelated host.

2. List listening TCP and UDP sockets

Start with numeric output so DNS and service-name lookups do not slow the inspection or hide the actual endpoint:

$ netstat -lnt
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 127.0.0.1:5432        0.0.0.0:*               LISTEN
tcp6       0      0 :::22                  :::*                    LISTEN

-l selects listening sockets, -n keeps addresses and ports numeric, and -t selects TCP. Add -u for UDP: netstat -lnu. Use -a when you also need non-listening sockets, including established connections.

Read the local address carefully. 127.0.0.1:PORT is local to the host, while 0.0.0.0:PORT can accept IPv4 traffic on any local IPv4 address. For IPv6, :::PORT is the corresponding wildcard form. A wildcard listener may be intended, but it deserves a service and firewall review.

On a busy machine, keep the output manageable:

$ netstat -lnt | grep -E ':(22|80|443)\s'

This filters the displayed text; it does not change the sockets. The exact spacing differs between builds, so use the unfiltered command when an empty result could be misleading.

3. Identify the owning process

Add -p when you need the PID and program name:

$ netstat -lntp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address   Foreign Address State  PID/Program name
tcp        0      0 127.0.0.1:5432  0.0.0.0:*       LISTEN 1234/postgres

Process details are subject to normal ownership and kernel access rules. You may see a warning that not all processes could be identified and a hyphen instead of a PID. First try the command as your ordinary user. Use elevated privileges only when your investigation requires information owned by other users:

$ sudo netstat -lntp

Safety boundary

sudo only improves visibility here. It does not make an unknown listener safe, and it does not stop anything. Before stopping a service, record the listener, confirm the owning unit with your service manager, and use that manager's documented stop or disable operation. This guide deliberately makes no state-changing command.

4. Inspect current connections without name lookups

To see both servers and active connections, combine -a, -n and a protocol selector:

$ netstat -ant
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address      Foreign Address    State
tcp        0      0 127.0.0.1:5432     127.0.0.1:48122    ESTABLISHED
tcp        0      0 0.0.0.0:22        0.0.0.0:*          LISTEN

Common TCP states include LISTEN, ESTABLISHED, TIME_WAIT and CLOSE_WAIT. A single snapshot is not a history: sockets can disappear while netstat is printing them, and the manpage acknowledges that transient oddities can occur. Repeat the read before treating one line as proof of a persistent problem.

For a short live view, -c prints the selected information every second:

$ netstat -c -n -t

Press Ctrl-C to return to the shell. This stops netstat's display loop only; it does not stop network traffic.

5. Check routes and interfaces

Use -r for the kernel routing table:

$ netstat -rn
Kernel IP routing table
Destination     Gateway         Genmask         Flags Iface
0.0.0.0         192.0.2.1       0.0.0.0         UG    enp1s0
192.0.2.0       0.0.0.0        255.255.255.0   U     enp1s0

-n prevents host-name resolution, so the destination and gateway remain easy to compare with firewall or routing documentation. The default route is the row whose destination is 0.0.0.0. Use netstat -i for interface counters such as received, transmitted, dropped and errored packets:

$ netstat -i
Kernel Interface table
Iface  MTU  RX-OK RX-ERR RX-DRP TX-OK TX-ERR TX-DRP Flg
lo     65536  ...    0      0      ...    0      0     LRU

Counter values are cumulative since the interface or system reset. A non-zero number is a clue, not a diagnosis. Compare it over time and correlate it with link, driver and kernel logs before changing configuration.

6. Read protocol counters when a connection is failing

netstat -s prints protocol statistics. Narrow it when possible:

$ netstat -s --tcp
Tcp:
    ... active connection openings
    ... failed connection attempts
    ... segments retransmitted

The exact counters depend on the running kernel. Look for trends in failed opens, resets and retransmissions rather than treating one counter as a verdict. The command reads information exposed through /proc, including files such as /proc/net/tcp, /proc/net/route and /proc/net/snmp. If those interfaces are restricted or unavailable, the output may be incomplete.

Done means

  • You can list numeric TCP listeners with netstat -lnt and include UDP with -u.
  • You know that 127.0.0.1 and wildcard addresses have different exposure.
  • You use -p and, only when necessary, sudo to identify another user's process.
  • You can inspect routes with -rn, interface counters with -i and protocol counters with -s.
  • You have made no network-state change: stopping or reconfiguring the owning service remains a separate, deliberate task.