EMZETT.
Login

netstat

In short: A command that shows open ports, active connections and network statistics of your own computer.

In more detail: netstat (network statistics) shows which ports are listening on the computer and which remote systems it currently has connections with. On Linux ss is the modern successor. It is used to check whether a service is running and whether unexpected connections exist.

In Depth

Important options

CallEffect
netstat -anall connections and listening ports, numeric
netstat -anoadditionally the process ID (PID)
netstat -bthe associated program (administrator rights needed)
netstat -rrouting table
netstat -sstatistics per protocol ([[tcp
netstat -an | findstr :443only lines with port 443

Example output

  Proto  Local Address       Foreign Address    State
  TCP    0.0.0.0:80          0.0.0.0:0          LISTENING
  TCP    192.168.1.23:51234  76.76.21.21:443    ESTABLISHED
  UDP    0.0.0.0:68          *:*

States of a TCP connection

  • LISTENING: A service is waiting for connections.
  • ESTABLISHED: The connection is up, data flows.
  • TIME_WAIT: The connection was closed, the port is still reserved briefly.
  • SYN_SENT / SYN_RECEIVED: Setup in progress (three-way handshake).
  • CLOSE_WAIT: The remote side has closed, the local program has not yet.

Typical uses

  • Port in use? A server does not start because the port is already used? netstat -ano | findstr :3000 shows the PID, and in the task manager you find the program (see EADDRINUSE).
  • Is my service running? Is it in the list as LISTENING?
  • Suspicious connections: Use -b or -ano to find out which program talks to which address.
  • Firewall test: See whether a port is open only locally (127.0.0.1) or for everyone (0.0.0.0).

See also: Network Commands in the CMD, Port, TCP, Three-Way Handshake, EADDRINUSE: Port Already in Use, Firewall, Standard Port, CMD