What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To see which services are listening on a Linux machine, run sudo ss -tulnp. To find out whether another machine can reach those services, test from that machine or network with a tool such as nmap. These checks answer different questions: a local listener is not necessarily reachable through the host firewall, a router, or a cloud firewall.

Check listening ports with ss

Run:

sudo ss -tulnp

This lists listening TCP and UDP sockets visible in the current network namespace. The options mean -t TCP, -u UDP, -l listening sockets, -n numeric addresses and port numbers, and -p process information. The sudo helps show the process that owns a socket; without it, ownership details may be missing.

For a simpler view with extended socket details, use sudo ss -tulpen. To focus on one protocol:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
# TCP listeners
sudo ss -ltnp

# UDP listeners
sudo ss -lunp

Checking both matters: a TCP-only listing will not show UDP services. TCP and UDP use separate port spaces, so 53/tcp and 53/udp are different sockets. Ports range from 0 to 65,535.

#1 Best Overall
UGREEN Cat 8 Ethernet Cable 6FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 6FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5

Typical output includes columns for network type, state, local address and port, peer address and port, and process. A TCP server socket usually has state LISTEN. UDP has no TCP-style connection state, so a ready UDP socket commonly appears as UNCONN. The local address identifies where the service is bound; the process field may look like users:(("sshd",pid=812,fd=3)).

Netid State  Local Address:Port  Peer Address:Port  Process
tcp   LISTEN 0.0.0.0:22          0.0.0.0:*          users:(("sshd",pid=812,fd=3))
tcp   LISTEN 127.0.0.1:5432     0.0.0.0:*          users:(("postgres",pid=940,fd=7))
udp   UNCONN 0.0.0.0:53         0.0.0.0:*          users:(("service",pid=500,fd=14))

Numeric output avoids translating ports into service names such as ssh or http, making results easier to compare and search. ss is the modern default on Linux systems using iproute2; older guides may use netstat, but ss is generally preferred. See the ss manual and Ubuntu’s open-port guidance.

Read the bind address, not just the port

  • 127.0.0.1:8080 is bound to IPv4 loopback and is normally accessible only from the same host.
  • [::1]:8080 is bound to IPv6 loopback.
  • 0.0.0.0:8080 listens on all local IPv4 interfaces.
  • [::]:8080 is an IPv6 wildcard bind. Whether it also accepts IPv4-mapped connections depends on the application and system configuration.
  • 192.168.1.10:8080 is bound to that particular local address.

A wildcard bind does not by itself mean the port is exposed to the Internet. A firewall, routing, NAT, or upstream network policy can still block access. Conversely, a proxy or forwarding rule can expose a service through a different address or port. Ubuntu explains why loopback listeners should be distinguished from ports reachable beyond the local machine in its guidance on unnecessarily open ports.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Filter by port or address family

To inspect one TCP or UDP port:

sudo ss -ltnp 'sport = :8080'
sudo ss -lunp 'sport = :53'

To separate IPv4 and IPv6 listeners:

sudo ss -4 -ltnp
sudo ss -6 -ltnp

A service listening on IPv4 does not necessarily listen on IPv6, or vice versa. If a filter is not accepted on an older distribution, check man ss for that system’s filter syntax. To inspect listening Unix-domain sockets—which are local IPC endpoints, not network ports—use sudo ss -lxp.

Find which process owns a port

The -p option to ss is usually enough. For example:

sudo ss -ltnp 'sport = :8080'

You can also use lsof to associate sockets with processes:

Rank #2
UGREEN Cat 8 Ethernet Cable 10FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 10FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5
sudo lsof -nP -i :8080

# TCP listeners or UDP sockets
sudo lsof -nP -iTCP -sTCP:LISTEN
sudo lsof -nP -iUDP

Here, -i selects network sockets, -n avoids hostname lookups, -P keeps port numbers numeric, and -sTCP:LISTEN restricts the first listing to TCP listeners. lsof may not be installed, and complete process details can require root privileges. Its options are documented in the lsof manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you have a process ID but do not recognize it, inspect it before stopping anything:

ps -fp PID
sudo readlink -f /proc/PID/exe
sudo systemctl status SERVICE

Replace PID and SERVICE with the actual values. To review active services, run systemctl --type=service --state=running. A listener can belong to a system service, a user process, a container, or a socket-activated service; do not kill it or disable its unit until you understand its purpose and dependencies.

Test reachability from another machine

To test what a particular network can reach, run the scan from a different host on that network. With Nmap, select the target and ports explicitly:

nmap -Pn -p 22,80,443 192.0.2.10

-p selects ports. -Pn skips host discovery and treats the target as online, which is useful when ping or other discovery probes are blocked. To scan all TCP ports (1–65,535):

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nmap -Pn -p- 192.0.2.10

To request service/version detection on selected ports, use -sV. UDP requires an explicit scan; for example:

Rank #3
Ethernet Cable 15 ft, Cat7 High Speed Flat Shielded Internet Network Cable
  • Hyper Speed Performance: Cat7 Ethernet Cable provides perfect performance of 600 MHz bandwidth and 10 Gbps high speed data transmission which is faster than Cat5 and Cat6. No worries about network delay when playing games, streaming 4K Videos, and downloading
  • Stability & Durability: Gold-plated RJ45 connectors are for higher sensitivity and better stability; 4 Pairs STP cable of 100% thick copper wire ensure faster Internet speed; Each twisted pair contain one ground wire which can effectively reduce noise & interference
  • Great Compatibility: Cat7 Ethernet cable can be used for Wi-Fi routers, Xbox one, Computer data center, Cloud Server, Network media players, PS4, Hubs and other device with RJ45 connectors. And also this could be backward compatible with Cat5e, Cat5, Cat6 and much more faster than them
  • Flexible Design: Unique flat cord makes this lan cable super flexible and allows for a cleaner and safer installation; It is much easier for you to make the network cable run along walls, follow edges & corners or slide it under a carpet; It can effectively avoid tangling and save space
  • Professional Certifiacted: All the Cat7 Ethernet cables pass analyzers tested; Manufactured with upgraded jacket, Folishine Cat 7 cables are waterproof, durable and pull-resistant for heavy duty work; Suitable for both outdoor and indoor use without rusting
nmap -Pn -sV -p 22,80,443 192.0.2.10
sudo nmap -Pn -sU -p 53,123,161 192.0.2.10

# A selection of common UDP ports
sudo nmap -Pn -sU --top-ports 50 192.0.2.10

Nmap’s normal scan is not a scan of every TCP and UDP port. A full TCP scan uses -p-, while UDP must be requested with -sU. UDP scans may be slow or inconclusive: no response can mean an open service ignored the probe, or that a firewall silently dropped it. Confirm uncertain results with an appropriate protocol-specific request, service logs, or a targeted probe. Nmap describes these states in its reference guide and manual page.

Common results include:

  • open: a service accepted or responded to the probe.
  • closed: the host is reachable at that port, but no application is accepting the probe.
  • filtered: a filter or network obstacle prevents Nmap from deciding whether the port is open or closed.
  • open|filtered: Nmap cannot distinguish an open port from one whose probes were silently filtered; this is common with UDP.

These are observations from the scanner’s location and at the time of the test, not permanent attributes of a port. Scan only machines and networks you own or are authorized to test.

For a one-off TCP connection test, netcat is simpler:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nc -vz 192.0.2.10 443

To test a service on the same machine, use its loopback address, for example nc -vz 127.0.0.1 8080. Netcat implementations differ, and this quick test does not provide Nmap’s port-state classification or UDP scanning capabilities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Inspect the firewall separately

A firewall rule permitting a port does not prove a service is listening. A listener does not prove the firewall permits traffic. Use the tool for the firewall framework actually active on your distribution, then verify with a remote test.

Ubuntu and UFW

sudo ufw status verbose
sudo ufw status numbered

UFW is Ubuntu’s simplified firewall configuration tool, built on Netfilter. Its status is useful, but it cannot show whether an upstream router or cloud firewall will permit traffic. See Ubuntu Server’s firewall documentation.

Rank #4
UGREEN Cat 8 Ethernet Cable 15FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 15FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5

nftables

sudo nft list ruleset

This displays the nftables ruleset. Understanding the effective policy may require interpreting tables, chains, hooks, and default policies. Ubuntu outlines the relationship among Netfilter, nftables, iptables, and UFW in its firewall documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

firewalld

sudo firewall-cmd --state
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --list-all
sudo firewall-cmd --list-ports
sudo firewall-cmd --list-services

Firewalld uses zones, and the active zone matters for the interface carrying the traffic. It also distinguishes named services from explicit port rules. Permanent changes and runtime changes can differ; consult the firewalld guidance before changing policy.

Legacy iptables

sudo iptables -L -n -v
sudo ip6tables -L -n -v

On modern distributions, these commands may use an iptables compatibility interface backed by nftables. An iptables listing alone may not reveal the complete active policy, so identify the system’s firewall framework before drawing conclusions.

Why local and remote results can disagree

  • Localhost-only bind: ss shows a service on 127.0.0.1 or ::1, so another host cannot connect directly. If remote access is intended, configure the application’s bind address appropriately; merely opening a firewall rule will not change a loopback-only bind.
  • Host or upstream firewall: ss reports a local socket, while Nmap may report filtered because of the Linux firewall, a router, network ACL, or provider firewall.
  • Different address family: an IPv4 test does not establish IPv6 reachability. Check ss -4 and ss -6, and test the relevant address family from outside.
  • Containers and namespaces: host output may not show all sockets in another network namespace. Check runtime configuration, for example docker ps and docker port CONTAINER, and inspect the relevant namespace where appropriate. ss normally reports the shell’s namespace; Ubuntu documents the -N option for inspecting another named namespace, such as sudo ss -N NAMESPACE -tulnp.
  • NAT, forwarding, or reverse proxy: a router, container publishing rule, or proxy may expose a public port and forward it to a different internal address or port. Check both the public-facing listener or mapping and the backend service.
  • Cloud policy: security groups, network ACLs, routing, public versus private IPs, and load-balancer listeners can control exposure independently of the host. A public load balancer can expose traffic even when the backend host is not directly reachable.
  • Systemd socket activation: systemd may hold a listening socket and start the service only when a connection arrives. Check systemctl list-sockets and then the relevant SERVICE.socket unit with systemctl status SERVICE.socket.

If a port should not be exposed, first identify its owner and intended use. Depending on the cause, the safe fix may be to stop or disable a service, change its bind address, remove a firewall exception, correct a container publishing rule, or change a cloud security rule. Re-test afterward from the network whose access matters. Do not assume that an empty TCP listing proves a host is secure: UDP, IPv6, other namespaces, forwarding, and application vulnerabilities also matter.

A practical troubleshooting sequence

  1. List local TCP and UDP listeners: sudo ss -tulnp.
  2. Inspect the particular port and identify its process: sudo ss -ltnp 'sport = :PORT', or sudo lsof -nP -i :PORT.
  3. Check whether the service is bound to loopback, a specific interface, or a wildcard address; check IPv4 and IPv6 if relevant.
  4. Inspect the active local firewall with the appropriate tool: UFW, nftables, or firewalld.
  5. Check any container mapping, router/NAT rule, load balancer, or cloud network policy in the path.
  6. From another machine on the relevant network, test the exact host address and port with nmap -Pn -p PORT HOST or a TCP check such as nc -vz HOST PORT.

If ss, lsof, or Nmap is missing, install the package for your distribution or use another authorized Linux host. For example, Debian/Ubuntu systems commonly provide Nmap through sudo apt install nmap, and Fedora/RHEL-compatible systems through sudo dnf install nmap. Prefer ss over installing legacy net-tools solely to get netstat.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.