How to Use the netstat Command on Linux
Learn netstat on Linux: inspect ports, sockets, routes, interfaces, owning processes, troubleshooting steps, and modern ss alternatives.
Direct answer: use netstat -tuln to list listening TCP and UDP sockets with numeric addresses and ports. Add -p to request the owning process and PID (usually with root privileges): sudo netstat -tulpn. Use -a for listening and non-listening sockets, -r for routes, -i for interface counters, -g for multicast memberships, and -s for protocol statistics.
netstat is part of the net-tools collection. The current netstat(8) manual describes it as mostly obsolete and points to ss as its replacement. Keep netstat in your toolbox for existing systems and scripts, but prefer ss for new socket inspection, especially on busy hosts.
Install or verify netstat
Check whether it is already available:
command -v netstat
netstat --version
If the command is missing, install the distribution package that provides net-tools using your normal package-management process. Package names and installation commands vary by distribution and release, so verify them in your distribution documentation.
Understand the netstat command shape
netstat [options]
| Option | Meaning | Typical use |
|---|---|---|
-t |
TCP sockets | Inspect TCP listeners or connections |
-u |
UDP sockets | Inspect UDP listeners or endpoints |
-l |
Listening sockets only | Find services waiting for connections |
-n |
Numeric addresses and ports | Avoid DNS and service-name lookups |
-p |
Process and PID information | Find which program owns a socket |
-a |
All sockets | Include active and listening sockets |
-r |
Routing table | Inspect kernel routes |
-i |
Interface statistics | Check packets, errors and drops |
-e |
Extended information | Add interface or socket detail |
-g |
Multicast memberships | See multicast groups |
-s |
Protocol statistics | Summarize TCP, UDP and IP counters |
Find listening ports
TCP and UDP listeners
netstat -tuln
Typical columns are Proto, Recv-Q, Send-Q, Local Address, Foreign Address and State. With -n, addresses and ports remain numeric, which makes output faster to read and safer to parse in scripts.
Include the owning program and PID
sudo netstat -tulpn
The -p option requests process attribution. The manual notes that root is required for the complete view and that attribution is not fully reliable. A dash or missing name can result from permissions, a kernel-owned socket, or a process that exited; it does not prove that no process owns the endpoint.
Ask which process listens on port 8080
sudo netstat -tulpn | grep ':8080'
For scripts, match the numeric port and account for IPv4 and IPv6 forms:
sudo netstat -tulpn | grep -E '(:|\.)8080([[:space:]]|$)'
Show active as well as listening sockets
netstat -tuan
Adding -a includes established and other non-listening sockets. TCP states such as ESTABLISHED describe connection state; UDP commonly has no state value.
Read addresses, states and reachability correctly
- Local Address is the local IP and port.
0.0.0.0:8080means an IPv4 wildcard bind;[::]:8080is an IPv6 wildcard form. - Foreign Address is the peer endpoint when a connection exists.
- LISTEN means a local socket is waiting for connections. It does not prove that the service is reachable from the public internet: binding address, firewall rules and network path still matter.
- Without
-n, netstat may resolve hostnames and map ports to service names. That can be slower and can make exact matching harder.
Inspect routes, interfaces and protocol counters
Routing table
netstat -rn
-r selects routes and -n keeps gateway and destination values numeric. The modern equivalent documented by net-tools is:
ip route
Interface counters
netstat -i
netstat -ie
The second command adds extended interface detail. Look for increasing receive or transmit errors, drops and overruns. The corresponding modern command is:
ip -s link
Multicast memberships
netstat -g
Use ip maddr for the modern equivalent.
Protocol statistics
netstat -s
netstat -st
netstat -su
The first prints protocol summaries; the latter two narrow the summary to TCP or UDP.
Useful diagnostic recipes
| Question | Command |
|---|---|
| Which TCP ports are listening? | netstat -ltn |
| Which UDP ports are listening? | netstat -lun |
| Which program owns listeners? | sudo netstat -lntup |
| What connections are established? | netstat -tn |
| Show every TCP socket | netstat -tan |
| Inspect one port | sudo netstat -lntup | grep ':443' |
| Show routes numerically | netstat -rn |
| Show interface counters | netstat -i |
| Show TCP errors and counters | netstat -st |
Use netstat safely in scripts
Prefer -n to avoid DNS delays and service-name changes. Treat whitespace as variable and avoid assuming a fixed column width. Check the exit status, handle an empty result as a valid state, and remember that process fields can be unavailable without privileges.
#!/usr/bin/env bash
set -euo pipefail
port=${1:?usage: $0 PORT}
if sudo netstat -lntup 2>/dev/null | grep -qE ":${port}[[:space:]]"; then
echo "port ${port} is listening"
else
echo "port ${port} is not shown as listening"
fi
Prefer ss for new Linux tooling
The iproute2 ss manual describes ss as a socket-statistics utility with similar information and more TCP and state detail. The net-tools manual specifically recommends it because netstat can be slow when listing many sockets on a busy server.
ss -ltn
ss -lun
sudo ss -lntup
ss -ta
ss -ua
| Need | Legacy command | Modern command |
|---|---|---|
| TCP listeners | netstat -ltn |
ss -ltn |
| All TCP sockets | netstat -tan |
ss -ta |
| Routes | netstat -rn |
ip route |
| Interface counters | netstat -i |
ip -s link |
| Multicast groups | netstat -g |
ip maddr |
Performance, permissions and reliability notes
- Use numeric mode (
-n) when diagnosing latency or processing output; name resolution can add delays. - On hosts with many sockets, netstat’s listing performance can be low. Use
ss, which uses the netlink interface. - Run with appropriate privileges when process ownership matters. Even then, attribution may be incomplete or unreliable.
- Repeat a command when investigating a transient connection. A socket can close between observation and action.
- Listening state is local evidence only. Confirm firewall and routing behavior separately.
Troubleshooting common errors
netstat: command not found
net-tools is not installed or the binary is outside PATH. Install the package for your distribution, or use ss if iproute2 is present.
Process column shows -
Use sudo. If it remains blank, permissions, a kernel socket or a process that exited may explain it. Do not conclude that the port is unused from this field alone.
The command is slow or appears stuck
Use -n to disable lookups, narrow the protocol and listening state, or switch to ss. Large socket tables are a known netstat weakness.
A service listens but clients cannot connect
Check the bound local address, host firewall, upstream firewall, route and whether the client is using IPv4 or IPv6. A LISTEN row alone does not establish reachability.
The expected port is absent
Check both protocols, remove -l if you expect an established connection, verify the service configuration and inspect ss -lntup. Confirm that the service has started in the same network namespace as the command.
Names and ports look unfamiliar
Rerun with -n. Without it, netstat resolves addresses and translates numeric ports into service names.
Or skip the browser setup
If you are documenting network diagnostics and need clean screenshots of a dashboard or status page, ScreenshotNeo returns an image or PDF from one GET request. See the ScreenshotNeo API documentation.
curl -G 'https://api.screenshotneo.com/v1/shot' -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://example.com'}, timeout=90)
open('shot.webp', 'wb').write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Before capture, cookie and consent banners, newsletter popups and chat widgets are removed. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers report the page verdict and billing result. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
FAQ
Is netstat still installed by default?
Availability depends on the Linux distribution and image. Many current systems provide ss through iproute2 instead.
Does -l show outbound connections?
No. It selects listening sockets. Remove -l, or use -a, to include non-listening sockets.
Why use -n when troubleshooting?
It avoids DNS and service-name resolution, keeps output numeric and makes filtering deterministic.
Can netstat prove a port is open to the internet?
No. It reports local socket state. Firewall rules, binding addresses and network paths determine external reachability.
What is the closest replacement for netstat?
Use ss for sockets, ip route for routes, ip -s link for interface counters and ip maddr for multicast memberships.


