How to Check Open Ports in Linux

If you just installed a new web server (like Apache or Nginx) but you cannot access your website from a web browser, the very first troubleshooting step is to verify that the server software is actually listening for traffic on the correct network port (Port 80 for HTTP, Port 443 for HTTPS). Conversely, if you are auditing a server for security vulnerabilities, you must scan the machine to ensure no rogue, unauthorized applications are secretly opening ports to the outside internet.

You do not need to install complex third-party port scanners to check your local machine. Linux has powerful network diagnostic tools built directly into the core operating system.

Method 1: The ss Command (The Modern Standard)

For decades, systems administrators relied on the venerable netstat command. However, netstat was officially deprecated years ago because it struggles to quickly process the massive routing tables on modern, high-traffic servers. It has been completely replaced by the ss (Socket Statistics) command, which is faster and vastly more detailed.

  1. Open your terminal and connect to your server.
  2. You must run the command with administrator privileges (sudo) to see exactly which software process owns which port. Type the following command and press Enter:
sudo ss -tulpn

This command uses a highly specific combination of flags to filter out the noise:

  • -t: Show only TCP ports.
  • -u: Show only UDP ports.
  • -l: Show only “listening” sockets (ports that are actively waiting for an incoming connection).
  • -p: Show the specific Process ID (PID) and the name of the software using the port.
  • -n: Show the raw numeric port numbers (e.g., 80) instead of trying to resolve them into human-readable service names (e.g., “http”), which is much faster.

The terminal will print a perfectly formatted table. Look at the Local Address:Port column to see exactly which ports are open (e.g., 0.0.0.0:22 means Port 22 is open to the entire internet). Look at the far right Process column to see exactly which software is controlling it (e.g., sshd).

Method 2: The lsof Command (The File Explorer Method)

Because everything in Linux is technically a “file” (including network connections), you can use the lsof (List Open Files) command to query the network stack. This is incredibly useful if you want to check the status of one highly specific port, rather than printing a massive table of every port on the machine.

If you want to know exactly what software is squatting on Port 80 and preventing your web server from starting, type the following command:

sudo lsof -i :80
  • The -i flag tells the command to only look at internet network files.
  • The :80 specifically targets Port 80.

If the port is empty, the command will return absolutely nothing. If the port is currently being used, it will print a single row of data explicitly naming the software (e.g., apache2) and giving you the Process ID (PID) so you can forcefully kill the rogue software using the kill -9 command.

Method 3: The UFW Firewall Check

If the ss command proves that Nginx is actively listening on Port 80, but your website still won’t load in a browser, your software is working perfectly. The problem is your firewall. The port is open on the software side, but the operating system is violently blocking the traffic at the front door.

To check the status of the Uncomplicated Firewall (UFW) on Ubuntu, type:

sudo ufw status

This will print a list of every port that is legally allowed to receive traffic from the outside world. If Port 80 or Port 443 are missing from that list, you must manually punch a hole in the firewall using sudo ufw allow 80/tcp.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.