Linux Netstat Command Explained
What Is Netstat? Netstat (Network Statistics) is a command-line utility used to monitor incoming and outgoing network connections, interface statistics,...
What Is Netstat?
Netstat (Network Statistics) is a command-line utility used to monitor incoming and outgoing network connections, interface statistics, routing tables, and more.
It’s available in most Linux distributions and part of the net-tools package (which may need to be installed on newer systems).
Installing Netstat on Linux
On newer Linux systems (like Ubuntu 20.04+), netstat might not be installed by default. You can install it with:
sudo apt install net-tools # Debian/Ubuntu
sudo yum install net-tools # CentOS/RHEL
sudo dnf install net-tools # Fedora
To verify:
netstat –version
Basic Syntax of Netstat
netstat [options]
Common syntax examples:
| Command | Description |
| netstat -a | Show all active connections and listening ports |
| netstat -t | Display TCP connections |
| netstat -u | Display UDP connections |
| netstat -l | Show only listening sockets |
| netstat -p | Show PID and program name for connections |
| netstat -n | Show numerical addresses instead of resolving hostnames |
| netstat -r | Display routing table |
| netstat -i | Display network interface statistics |
Examples of Netstat Commands in Linux
Let’s explore real-world netstat commands linux users frequently rely on.
1. Show All Active Connections
netstat –a
This command displays all connections both listening and non-listening sockets.
2. Display Only Listening Ports
netstat -l
Useful to see which services are actively listening for incoming connections.
Combine with protocol filters:
netstat –lt # TCP only
netstat -lu # UDP only
netstat -lx # Unix domain sockets
3. Show Active TCP Connections
netstat –at
This provides a summary of TCP connections including their states (e.g., ESTABLISHED , TIME_WAIT , LISTEN ).
Example output:
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 localhost:ssh 192.168.1.5:52576 ESTABLISHED
tcp6 0 0 [::]:http [::]:* LISTEN
4. Display UDP Connections
netstat -au
Since UDP is connectionless, you won’t see connection states here — only active sockets.
5. Show Numerical IPs Instead of Hostnames
netstat -an
This speeds up the output and avoids DNS lookups.
It’s very handy for scripting or quick analysis.
6. Show Process Names / PIDs Using Ports
sudo netstat -tulpn
- t – TCP
- u – UDP
- l – Listening
- p – Process
- n – Numeric output
This command shows which process is listening on which port.
7. Show Routing Table
netstat –r
This displays the system’s IP routing table similar to the route -n command.
Example:
Kernel IP routing table
Destination Gateway Genmask Flags Iface
default 192.168.0.1 0.0.0.0 UG eth0
192.168.0.0 0.0.0.0 255.255.255.0 U eth0
8. Display Interface Statistics
netstat –i
This shows each network interface, its MTU, and the number of packets received/transmitted.
Example:
Kernel Interface table
Iface MTU Met RX-OK RX-ERR RX-DRP TX-OK TX-ERR TX-DRP Flg
eth0 1500 0 2249 0 0 1943 0 0 BMRU
9. Find Services Listening on a Specific Port
sudo netstat -tulpn | grep :80
This filters to show only services running on port 80 (HTTP).
10. Continuous Monitoring with Watch
You can combine netstat with watch for real-time updates:
watch -n 2 netstat -tulpen
This refreshes the output every 2 seconds.
Combine Netstat with Grep for Quick Searches
To find all active SSH connections:
netstat -tnp | grep ssh
To list connections from a specific IP:
netstat -an | grep 192.168.1.100
Modern Alternative: ss Command
netstat is powerful but somewhat outdated.
The ss (socket statistics) command is the modern alternative included by default in most systems.
Example equivalents:
| Netstat Command | Equivalent ss Command |
| netstat -tuln | ss -tuln |
| netstat -p | ss -p |
| netstat -s | ss -s |
Example:
ss -tulwn
Keep Reading
More from the blog
Guides, tutorials, and insights on RDP hosting and cloud infrastructure.



