ss
NetworkPackage: iproute2
The open sockets: who listens on which port, which connections are established, and with -p which process. ss -tlnp is the command that answers "is something already listening on 80?"
What its options do in the lessons
From the same glossary the lessons render under their commands, so the two cannot disagree.
ss -t- TCP sockets.
ss -u- UDP sockets, as
-tdoes for TCP. The two are exclusive in one invocation:ss -uanshows no TCP socket at all. ss -a- Shows listening sockets as well as established connections. Without it, a service waiting with no client does not appear at all.
ss -l- Only listening sockets — what is accepting connections.
ss -n- Prints port numbers without translating them into service names, so no DNS lookups.
ss -p- Shows which process owns each socket (needs root).
Lessons that teach it
- Your first systemd unitManaging services with systemd
- A port names a program, not a doorPorts, TCP and UDP: how two programs talk
- A connection is an agreement between two kernelsPorts, TCP and UDP: how two programs talk
- TCP or UDP: what to do when a packet is lostPorts, TCP and UDP: how two programs talk
- Getting an address when you have none yetPorts, TCP and UDP: how two programs talk
- From a name to a byte: five steps, and what each failure provesPorts, TCP and UDP: how two programs talk
- Ports: a process listens, or nothing answersNetworking: how your server is reached
- Refused or silent: what each failure provesNetworking: how your server is reached
- Unreachable: find the broken layer before touching anythingNetworking: how your server is reached
- Works on the server, refused from outsideNetworking: how your server is reached
- Reverse proxying a Node applicationHosting a web application with Nginx
- Creating a site, then putting a Node.js application on itISPConfig: hosting several sites on one server
- ufw: deny by default without locking yourself outFirewall and hardening
- The periodic checkFirewall and hardening
- The check that cannot fail, and the flush that proves nothingDiagnosing a failure: what each output proves
- From a symptom to one component: what the hypothesis forbidsDiagnosing a failure: what each output proves
- Capture before you repair: the state a fix deletesDiagnosing a failure: what each output proves
- Data outlives the container, the port goes through the firewallDocker: containers for hosting a Node application
- Reachable from elsewhere: four gates, four different refusalsAdministering PostgreSQL: access, connections and growth
