ss Commands Reference

Socket statistics from iproute2 — the modern replacement for netstat when checking listeners and established TLS connections.

📦 Availability

# Usually preinstalled with iproute2
ss -V
# Debian/Ubuntu: sudo apt install iproute2

👂 Listening ports

ss -tulpn                 # TCP/UDP listeners with process names
ss -tlnp 'sport = :443'   # Who is listening on 443
ss -tlnp 'sport = :80'

🔗 Established connections

ss -tpn                   # Established TCP + processes
ss -tpn 'dport = :443'    # Outbound HTTPS
ss -tpn 'sport = :443'    # Inbound HTTPS
ss -s                     # Summary statistics

🛠️ Useful filters

ss -tan state syn-sent
ss -tan state time-wait
ss -ltn src 10.0.0.0/8
ss -H -o state established '( dport = :443 or sport = :443 )'

-p often needs root to show other users' processes.

🔗 See Also