Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
containers

How to Check Established Network Connections in a Docker Container

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a running Linux container, the direct command is docker exec <container> ss -tan state established. It lists the container’s established TCP sockets, provided the image includes ss. The important detail is that the command runs in the container’s network namespace, not merely on the Docker host.

Run the established-connection check

Replace web with the container name or ID:

docker exec web ss -tan state established

docker exec starts a command in an already running container. The command must be an executable that exists in the image, and it works only while the container’s primary process is running.

Part Meaning
docker exec web Run a process in the network and process view of the running web container.
ss Linux socket-inspection utility.
-t Restrict the listing to TCP sockets.
-a Include listening and non-listening sockets before the state filter is applied.
-n Show numeric addresses and ports instead of resolving names.
state established Keep only sockets whose TCP state is ESTAB or ESTABLISHED.

The result is a point-in-time snapshot. A connection can close immediately after the command reads the socket table, so an empty result does not prove that an application never connected.

Check prerequisites first

  • Docker must be able to address the target container on the machine where you run the command.
  • The container must be running. A stopped container has no live socket table for docker exec to inspect.
  • The image must contain an executable named ss, or you must use another inspection path.
  • You need enough permission to execute a process in the container. Additional permission may be needed when requesting process ownership details.

Find the exact name or ID with docker ps. If several containers use similar names, use the full ID or select the intended instance explicitly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand the output

A typical numeric listing has columns similar to these:

State   Recv-Q  Send-Q  Local Address:Port  Peer Address:Port
ESTAB   0       0       172.18.0.4:8080    172.18.0.7:53124
  • State is the current TCP state.
  • Recv-Q and Send-Q are queued bytes waiting to be read or transmitted.
  • Local Address:Port identifies the container-side endpoint.
  • Peer Address:Port identifies the remote endpoint as seen from that network namespace.

Because -n disables name resolution, numeric output is faster to interpret and avoids confusing reverse-DNS names with the actual peer address. IPv4 and IPv6 sockets can both appear.

Show the owning process when needed

Add -p:

docker exec web ss -tanp state established

This asks ss to include process information. Whether a PID or process name is visible depends on the container’s permissions, process view, and security configuration; do not assume every row will have attribution.

You can also narrow the query. For example, this asks for established TCP sockets involving port 443:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker exec web ss -tan state established '( dport = :443 or sport = :443 )'

Use the local port when you want to verify a server socket, and the destination port when you want to identify outbound traffic. Keep the filter expression quoted so the shell does not interpret its parentheses.

Use the equivalent command with Docker Compose

For a Compose service, run:

docker compose exec web ss -tan state established

Here web is the service name, not necessarily a container name. If the service is scaled to multiple replicas, list the running containers and target the particular replica whose connections you need; otherwise you may inspect a different instance from the one handling the request.

What to do when ss is not installed

Small production images commonly omit diagnostic programs. docker exec does not install a missing executable, so choose an approach that fits your change-control and security policy.

Use a utility already present

Some images provide netstat instead. First check without changing the container:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker exec web command -v netstat
docker exec web netstat -tn

Look for rows whose state column is ESTABLISHED. Output columns and filtering syntax vary between implementations, so treat this as an image-specific fallback rather than a portable replacement for ss.

Attach an approved diagnostic container

An organization-approved diagnostic image can be placed in the target container’s network namespace and run a socket utility there. Confirm the image provenance, allowed capabilities, data-handling rules, and cleanup procedure before attaching it. The key requirement is the namespace: a tool in a different namespace will list the wrong sockets.

Inspect the namespace from the Linux host

On a Linux Docker host, you can use the target process’s network-namespace handle. The host must provide the required utilities and permit access to the process namespace.

  1. Get the container’s init-process PID:
PID=$(docker inspect --format '{{.State.Pid}}' web)
printf '%sn' "$PID"

Verify that the PID is nonzero and that /proc/$PID/ns/net exists before continuing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Create a temporary namespace name and map it to the process’s network namespace:
sudo mkdir -p /var/run/netns
sudo ln -s "/proc/$PID/ns/net" /var/run/netns/container-net
  1. Run the host’s socket utility in that namespace:
sudo ip netns exec container-net ss -tan state established
  1. Remove the temporary mapping when finished:
sudo rm /var/run/netns/container-net

This is a Linux-host technique. Distribution packaging, container runtime behavior, permissions, and the availability of ip or ss differ, so validate it in your environment. If the container is replaced, the old PID and namespace handle are no longer the right target.

Why host-wide commands and network inspection can mislead

Running ss directly on the Docker host may show host sockets and connections from many containers. Published ports and NAT rules also describe how traffic is exposed, not the complete live socket list inside one container.

docker network inspect is useful for network configuration and topology—such as attached endpoints and addressing—but it is not a live established-TCP report. Use a socket utility in the target namespace for connection state.

Method Best use Main limitation
docker exec … ss Fast, precise inspection when the image includes ss. Requires a running container and an installed executable.
Approved diagnostic container Minimal images where policy permits temporary tooling. Requires the correct namespace, image approval, and permissions.
Host namespace method Linux hosts where the container cannot be modified. Needs host-level access and compatible namespace utilities.
docker network inspect Network configuration and membership. Does not list live established sockets.

Or skip the browser setup

If you also need a clean image of a web dashboard, status page, or incident report for documentation, ScreenshotNeo can return a screenshot or PDF through one request. Its cleanup step accepts cookie-consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing result in headers. Its MCP server lets Claude, Cursor, and other MCP clients call screenshot tools directly.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See the parameter reference in the ScreenshotNeo documentation. A one-call example is:

Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://freedom251.com -o shot.webp

The same request from Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://freedom251.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

And from Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://freedom251.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 screenshots, and every feature is included on every plan. Create a free ScreenshotNeo account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common failures

Symptom Likely cause Fix
container ... is not running The target’s primary process has stopped. Check docker ps -a, restart or start the intended container if appropriate, then rerun the command.
exec: "ss": executable file not found The image does not contain ss. Use an available utility, an approved diagnostic container in the same namespace, or the Linux host-side method.
Permission denied for -p Process attribution is restricted by permissions or the container’s process view. Run the basic socket query, or obtain the minimum approved privilege needed for attribution.
No rows are returned No TCP socket was established at that instant, the traffic is UDP, or the command ran in the wrong namespace. Repeat during the request, confirm the application uses TCP, and verify the container or namespace target.
Only host traffic appears ss was run on the host rather than in the container namespace. Use docker exec or the namespace method against the specific container PID.
Compose output belongs to the wrong replica The service has multiple running instances. Enumerate the instances and execute against the intended container ID.
The namespace command fails after a redeploy The PID or namespace symlink refers to a replaced container. Remove the old mapping, obtain the new PID, create a new mapping, and rerun.

Operational notes for repeat checks

  • Sample deliberately: ss is a snapshot, not a history database. For intermittent connections, repeat the command during the suspected event or use an approved monitoring system.
  • Keep output reproducible: retain -n and record the container ID, timestamp, and host. Container names can be reused after replacement.
  • Separate TCP from UDP: the command uses -t; UDP sessions do not have TCP’s established state and require a different query.
  • Protect diagnostics: addresses, ports, and process names can reveal internal topology. Handle captured output according to your access and retention policy.
  • Do not assume a listening port is an active client: the state filter is what excludes listening-only sockets from the final result.

Frequently Asked Questions

Can this command inspect a container on another Docker host?

Not directly. Connect to the Docker host that runs the container, then execute the command there, using your organization’s approved remote-access method.

Does running ss change or interrupt connections?

No. It reads the socket table and reports the state; it does not close or reconfigure the sockets.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can I check a short-lived connection that disappears before I can run the command?

Collect repeated snapshots during the event or use an approved connection-monitoring system; a single ss invocation cannot reconstruct past sockets.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.