Read Listening Sockets and Routes with netstat
You will use netstat to answer the practical networking questions that usually matter first: what is listening, which addresses are exposed, which process owns a socket, what route the kernel will use, and whether an interface is dropping packets. The examples match net-tools 2.10, installed here as package version 2.10-0.1ubuntu4.4.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about 15 minutes. You need a shell and the net-tools package. These commands only read kernel networking information. They do not open ports, change routes, restart services or alter firewall rules.
1. Check the installed command
Confirm which binary will run and record its version:
$ command -v netstat
/usr/bin/netstat
$ netstat --version
net-tools 2.10
The output may include build features after the version line. That is normal. The command is old and the manpage calls it mostly obsolete, recommending ss for sockets, ip route for routes and ip -s link for interface statistics. It remains useful when you need its familiar output or a script already depends on it.
Checkpoint
If the command is missing, install the distribution package through your normal system administration process. Do not copy a binary from an unrelated host.
2. List listening TCP and UDP sockets
Start with numeric output so DNS and service-name lookups do not slow the inspection or hide the actual endpoint:
$ netstat -lnt
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 127.0.0.1:5432 0.0.0.0:* LISTEN
tcp6 0 0 :::22 :::* LISTEN
-l selects listening sockets, -n keeps addresses and ports numeric, and -t selects TCP. Add -u for UDP: netstat -lnu. Use -a when you also need non-listening sockets, including established connections.
Read the local address carefully. 127.0.0.1:PORT is local to the host, while 0.0.0.0:PORT can accept IPv4 traffic on any local IPv4 address. For IPv6, :::PORT is the corresponding wildcard form. A wildcard listener may be intended, but it deserves a service and firewall review.
On a busy machine, keep the output manageable:
$ netstat -lnt | grep -E ':(22|80|443)\s'
This filters the displayed text; it does not change the sockets. The exact spacing differs between builds, so use the unfiltered command when an empty result could be misleading.
3. Identify the owning process
Add -p when you need the PID and program name:
$ netstat -lntp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:5432 0.0.0.0:* LISTEN 1234/postgres
Process details are subject to normal ownership and kernel access rules. You may see a warning that not all processes could be identified and a hyphen instead of a PID. First try the command as your ordinary user. Use elevated privileges only when your investigation requires information owned by other users:
$ sudo netstat -lntp
Safety boundary
sudo only improves visibility here. It does not make an unknown listener safe, and it does not stop anything. Before stopping a service, record the listener, confirm the owning unit with your service manager, and use that manager's documented stop or disable operation. This guide deliberately makes no state-changing command.
4. Inspect current connections without name lookups
To see both servers and active connections, combine -a, -n and a protocol selector:
$ netstat -ant
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 127.0.0.1:5432 127.0.0.1:48122 ESTABLISHED
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
Common TCP states include LISTEN, ESTABLISHED, TIME_WAIT and CLOSE_WAIT. A single snapshot is not a history: sockets can disappear while netstat is printing them, and the manpage acknowledges that transient oddities can occur. Repeat the read before treating one line as proof of a persistent problem.
For a short live view, -c prints the selected information every second:
$ netstat -c -n -t
Press Ctrl-C to return to the shell. This stops netstat's display loop only; it does not stop network traffic.
5. Check routes and interfaces
Use -r for the kernel routing table:
$ netstat -rn
Kernel IP routing table
Destination Gateway Genmask Flags Iface
0.0.0.0 192.0.2.1 0.0.0.0 UG enp1s0
192.0.2.0 0.0.0.0 255.255.255.0 U enp1s0
-n prevents host-name resolution, so the destination and gateway remain easy to compare with firewall or routing documentation. The default route is the row whose destination is 0.0.0.0. Use netstat -i for interface counters such as received, transmitted, dropped and errored packets:
$ netstat -i
Kernel Interface table
Iface MTU RX-OK RX-ERR RX-DRP TX-OK TX-ERR TX-DRP Flg
lo 65536 ... 0 0 ... 0 0 LRU
Counter values are cumulative since the interface or system reset. A non-zero number is a clue, not a diagnosis. Compare it over time and correlate it with link, driver and kernel logs before changing configuration.
6. Read protocol counters when a connection is failing
netstat -s prints protocol statistics. Narrow it when possible:
$ netstat -s --tcp
Tcp:
... active connection openings
... failed connection attempts
... segments retransmitted
The exact counters depend on the running kernel. Look for trends in failed opens, resets and retransmissions rather than treating one counter as a verdict. The command reads information exposed through /proc, including files such as /proc/net/tcp, /proc/net/route and /proc/net/snmp. If those interfaces are restricted or unavailable, the output may be incomplete.
Done means
- You can list numeric TCP listeners with
netstat -lntand include UDP with-u. - You know that
127.0.0.1and wildcard addresses have different exposure. - You use
-pand, only when necessary,sudoto identify another user's process. - You can inspect routes with
-rn, interface counters with-iand protocol counters with-s. - You have made no network-state change: stopping or reconfiguring the owning service remains a separate, deliberate task.