CmdKeys LogoCommand Quiz

Netstat Command Practice

netstat prints a snapshot of the system's network state — connections, listeners, routing entries, interface counters, and per-protocol statistics — all in one command. This track drills the flag combinations that give you a targeted view: listening TCP ports, active UDP sockets, the routing table, and per-process socket ownership.

Command Reference

listen

CommandDescription
netstat -ltnShow only listening TCP sockets with numeric port numbers — no hostname or service-name resolution.
netstat -ltunpList all listening TCP and UDP ports with numeric addresses and the process name owning each socket.
netstat -lunShow only listening UDP sockets with numeric port numbers.
netstat -lxList all listening Unix domain sockets — useful for finding local IPC socket paths.
netstat -tlnpShow listening TCP sockets with numeric addresses and the PID/name of the owning process — fast, no DNS lookups.
netstat -ltunpList all listening ports (TCP + UDP) with numeric output and the process name — the most comprehensive single-command port audit.

interfaces

CommandDescription
netstat -iShow a table of all network interfaces with packet counts, errors, and drop statistics.
netstat -ieShow extended network interface information — equivalent to ifconfig output for each interface.
netstat -inShow network interface statistics with numeric addresses — avoids hostname lookups for interface IP addresses.
netstat -icContinuously refresh the interface statistics table every second — useful for monitoring throughput in real time.

connections

CommandDescription
netstat -aShow all sockets — both listening and active established connections across all protocols.
netstat -atShow all TCP sockets including listening and established — same as -a but restricted to TCP.
netstat -auShow all UDP sockets — both unconnected and connected UDP endpoints.
netstat -anShow all connections with numeric IP addresses and port numbers — no hostname or service-name resolution.
netstat -anpShow all connections with numeric addresses and the PID/name of the owning process — requires root for full cross-user visibility.

routing

CommandDescription
netstat -rDisplay the kernel IP routing table showing destinations, gateways, and interface assignments.
netstat -rnShow the routing table with numeric IP addresses — skips hostname resolution for gateway and destination fields.
netstat -rneShow the routing table with numeric addresses and extended fields including MSS, window size, and flags.
netstat -rvPrint the routing table with verbose output — includes additional route metadata not shown by -r alone.
netstat -rcContinuously refresh the routing table display every second — useful for watching route changes dynamically.

stats

CommandDescription
netstat -sDisplay aggregate statistics for all protocols — total packets, errors, drops, and retransmissions.
netstat -stDisplay TCP-specific statistics — retransmissions, connection resets, failed connection attempts.
netstat -suDisplay UDP-specific statistics — packets received, sent, errors, and unknown port messages.
netstat -vsDisplay verbose per-protocol statistics — includes additional counters not shown by -s alone.
netstat -cPrint netstat output continuously, refreshing every second — useful for watching connection counts change in real time.

combined

CommandDescription
netstat -anp | grep :<port>Filter all connections for a specific port number by piping numeric output into grep.
netstat -ltunp | grep <name>List all listening ports and filter by process name to find which port a specific service is bound to.
netstat -an | grep ESTABLISHEDShow only connections that are in the ESTABLISHED state — filters out listeners and connections in teardown.
netstat -an | grep TIME_WAIT | wc -lCount sockets in the TIME_WAIT state — a high number indicates rapid connection cycling and potential port exhaustion.
netstat -an | grep ESTABLISHED | wc -lCount the total number of currently established connections — useful for detecting unusual connection volume.

Key Use Cases

  • List every port currently listening for incoming connections with process names
  • Show all active TCP connections and their current state (ESTABLISHED, TIME_WAIT, etc.)
  • Print the routing table to diagnose gateway or route misconfiguration
  • Check per-protocol error and drop statistics to investigate packet loss
  • Show network interface statistics including bytes sent and received
  • Filter the output to a specific port using a netstat and grep pipeline

Frequently Asked Questions

What does -p do in netstat?

-p (program) appends the PID and name of the process that owns each socket to the output. It requires root or sudo on most systems to see processes owned by other users.

What is the difference between netstat -a and netstat -l?

-a shows all sockets — both listening and established. -l shows only listening sockets. Use -l to audit what ports are open for inbound connections, and -a when you also want to see active client connections.

Why use -n with netstat?

-n (numeric) suppresses hostname and service-name resolution. This makes output faster and avoids confusing entries where a port number maps to an unexpected service alias. Essential for scripting and large-scale output.

Is netstat deprecated and should I use ss instead?

On Linux, netstat is part of the legacy net-tools package and is considered deprecated in favor of ss (from iproute2), which reads socket state directly from the kernel and is faster on large tables. However, netstat remains installed on most systems and is universally available on BSD and macOS. ss is a separate tool with a different flag grammar.

Ready to master Netstat commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →