netstat
In short: A command that shows open ports, active connections and network statistics of your own computer.
In more detail: netstat (network statistics) shows which ports are listening on the computer and which remote systems it currently has connections with. On Linux ss is the modern successor. It is used to check whether a service is running and whether unexpected connections exist.
In Depth
Important options
| Call | Effect |
|---|---|
netstat -an | all connections and listening ports, numeric |
netstat -ano | additionally the process ID (PID) |
netstat -b | the associated program (administrator rights needed) |
netstat -r | routing table |
netstat -s | statistics per protocol ([[tcp |
netstat -an | findstr :443 | only lines with port 443 |
Example output
Proto Local Address Foreign Address State
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING
TCP 192.168.1.23:51234 76.76.21.21:443 ESTABLISHED
UDP 0.0.0.0:68 *:*States of a TCP connection
- LISTENING: A service is waiting for connections.
- ESTABLISHED: The connection is up, data flows.
- TIME_WAIT: The connection was closed, the port is still reserved briefly.
- SYN_SENT / SYN_RECEIVED: Setup in progress (three-way handshake).
- CLOSE_WAIT: The remote side has closed, the local program has not yet.
Typical uses
- Port in use? A server does not start because the port is already used?
netstat -ano | findstr :3000shows the PID, and in the task manager you find the program (see EADDRINUSE). - Is my service running? Is it in the list as LISTENING?
- Suspicious connections: Use
-bor-anoto find out which program talks to which address. - Firewall test: See whether a port is open only locally (
127.0.0.1) or for everyone (0.0.0.0).
See also: Network Commands in the CMD, Port, TCP, Three-Way Handshake, EADDRINUSE: Port Already in Use, Firewall, Standard Port, CMD