Ports and Sockets

Ports and Sockets: What ss -tlnp Tells You

An address gets a packet to the machine; a port gets it to a program, which opens a socket, binds it to an address and port, and listens. HTTP uses TCP 80 and HTTPS 443, and ports below 1024 need root or CAP_NET_BIND_SERVICE, which is why Apache 129 starts as root, binds port 80, then serves requests from workers running as www-data. ss replaces netstat: -t TCP, -l listening, -n numeric, and -p the owning process (other users' processes need sudo).

Every listening TCP socket except DNS, trimmed to page widthShell
sudo ss -tlnp | grep -v ':53 ' | cut -c1-94
Output
State  Recv-Q Send-Q  Local Address:Port  Peer Address:PortProcess
LISTEN 0      5             0.0.0.0:8086       0.0.0.0:*    users:(("python3",pid=716,fd=3))
LISTEN 0      5           127.0.0.1:8087       0.0.0.0:*    users:(("python3",pid=722,fd=3))
LISTEN 0      4096        127.0.0.1:8105       0.0.0.0:*    users:(("php",pid=1950,fd=4))
LISTEN 0      4096                *:3306             *:*    users:(("mysqld",pid=361,fd=21))
LISTEN 0      511                 *:80               *:*    users:(("apache2",pid=397,fd=4),("
LISTEN 0      70                  *:33060            *:*    users:(("mysqld",pid=361,fd=19))

The Python servers on 8086 and 8087 were started for this section's experiments. Local Address decides who can connect at all, before any firewall is consulted:

What the Local Address column of ss means
Local Address Accepts connections from Typical use
127.0.0.1:8087 This machine only Admin tools, PHP-FPM over TCP
0.0.0.0:8086 Any IPv4 address A public IPv4 service
*:80 Any IPv4 or IPv6 address Apache's Listen 80
172.23.167.60:80 Packets sent to that address One site per IP

For a listener, Send-Q is the backlog (511 is Apache's ListenBacklog default) and Recv-Q the connections waiting now; a Recv-Q near Send-Q means the server cannot keep up. Apache's Process column lists the parent and five workers, so it is cut off; sudo lsof 574 -nP -iTCP:80 -sTCP:LISTEN prints one line each, the parent as root and the workers as www-data.

Read the MySQL 524 lines as a warning. bind_address defaults to *, so 3306 and 33060 (the X Protocol) listen on every interface and only the firewall hides them; MySQL binds MySQL to 127.0.0.1. To see clients rather than listeners, run ss -tn state established '( sport = :80 )'.