Netstat Command Practice
netstat prints a snapshot of the system's network state — connections, listeners, routing entries, interface counters, and per-protocol statistics — all in one command. This track drills the flag combinations that give you a targeted view: listening TCP ports, active UDP sockets, the routing table, and per-process socket ownership.
Command Reference
listen
| Command | Description |
|---|---|
netstat -ltn | Show only listening TCP sockets with numeric port numbers — no hostname or service-name resolution. |
netstat -ltunp | List all listening TCP and UDP ports with numeric addresses and the process name owning each socket. |
netstat -lun | Show only listening UDP sockets with numeric port numbers. |
netstat -lx | List all listening Unix domain sockets — useful for finding local IPC socket paths. |
netstat -tlnp | Show listening TCP sockets with numeric addresses and the PID/name of the owning process — fast, no DNS lookups. |
netstat -ltunp | List all listening ports (TCP + UDP) with numeric output and the process name — the most comprehensive single-command port audit. |
interfaces
| Command | Description |
|---|---|
netstat -i | Show a table of all network interfaces with packet counts, errors, and drop statistics. |
netstat -ie | Show extended network interface information — equivalent to ifconfig output for each interface. |
netstat -in | Show network interface statistics with numeric addresses — avoids hostname lookups for interface IP addresses. |
netstat -ic | Continuously refresh the interface statistics table every second — useful for monitoring throughput in real time. |
connections
| Command | Description |
|---|---|
netstat -a | Show all sockets — both listening and active established connections across all protocols. |
netstat -at | Show all TCP sockets including listening and established — same as -a but restricted to TCP. |
netstat -au | Show all UDP sockets — both unconnected and connected UDP endpoints. |
netstat -an | Show all connections with numeric IP addresses and port numbers — no hostname or service-name resolution. |
netstat -anp | Show all connections with numeric addresses and the PID/name of the owning process — requires root for full cross-user visibility. |
routing
| Command | Description |
|---|---|
netstat -r | Display the kernel IP routing table showing destinations, gateways, and interface assignments. |
netstat -rn | Show the routing table with numeric IP addresses — skips hostname resolution for gateway and destination fields. |
netstat -rne | Show the routing table with numeric addresses and extended fields including MSS, window size, and flags. |
netstat -rv | Print the routing table with verbose output — includes additional route metadata not shown by -r alone. |
netstat -rc | Continuously refresh the routing table display every second — useful for watching route changes dynamically. |
stats
| Command | Description |
|---|---|
netstat -s | Display aggregate statistics for all protocols — total packets, errors, drops, and retransmissions. |
netstat -st | Display TCP-specific statistics — retransmissions, connection resets, failed connection attempts. |
netstat -su | Display UDP-specific statistics — packets received, sent, errors, and unknown port messages. |
netstat -vs | Display verbose per-protocol statistics — includes additional counters not shown by -s alone. |
netstat -c | Print netstat output continuously, refreshing every second — useful for watching connection counts change in real time. |
combined
| Command | Description |
|---|---|
netstat -anp | grep :<port> | Filter all connections for a specific port number by piping numeric output into grep. |
netstat -ltunp | grep <name> | List all listening ports and filter by process name to find which port a specific service is bound to. |
netstat -an | grep ESTABLISHED | Show only connections that are in the ESTABLISHED state — filters out listeners and connections in teardown. |
netstat -an | grep TIME_WAIT | wc -l | Count sockets in the TIME_WAIT state — a high number indicates rapid connection cycling and potential port exhaustion. |
netstat -an | grep ESTABLISHED | wc -l | Count the total number of currently established connections — useful for detecting unusual connection volume. |
Key Use Cases
- List every port currently listening for incoming connections with process names
- Show all active TCP connections and their current state (ESTABLISHED, TIME_WAIT, etc.)
- Print the routing table to diagnose gateway or route misconfiguration
- Check per-protocol error and drop statistics to investigate packet loss
- Show network interface statistics including bytes sent and received
- Filter the output to a specific port using a netstat and grep pipeline
Frequently Asked Questions
What does -p do in netstat?
-p (program) appends the PID and name of the process that owns each socket to the output. It requires root or sudo on most systems to see processes owned by other users.
What is the difference between netstat -a and netstat -l?
-a shows all sockets — both listening and established. -l shows only listening sockets. Use -l to audit what ports are open for inbound connections, and -a when you also want to see active client connections.
Why use -n with netstat?
-n (numeric) suppresses hostname and service-name resolution. This makes output faster and avoids confusing entries where a port number maps to an unexpected service alias. Essential for scripting and large-scale output.
Is netstat deprecated and should I use ss instead?
On Linux, netstat is part of the legacy net-tools package and is considered deprecated in favor of ss (from iproute2), which reads socket state directly from the kernel and is faster on large tables. However, netstat remains installed on most systems and is universally available on BSD and macOS. ss is a separate tool with a different flag grammar.
Ready to master Netstat commands?
Test your muscle memory with our spaced-repetition quiz system. Free forever.
