The Socket Interrogation Vector
In a headless Ubuntu server architecture, network communication is mathematically governed by ports—virtual endpoints numbered from 0 to 65535. When you deploy a web server like Nginx, it mathematically binds itself to Port `80` (HTTP) and `443` (HTTPS). If a rogue daemon (or a competing application like Apache) is already occupying that specific socket, Nginx will violently crash upon startup. To diagnose routing failures or to audit your server for unauthorized backdoors listening on obscure ports, you must instruct the Linux kernel to execute a comprehensive interrogation of the active TCP/UDP connection matrix.
How to Check Ports in Ubuntu
The legacy `netstat` utility has been mathematically deprecated in modern Ubuntu architectures. The `iproute2` suite replaced it with the significantly faster and more precise `ss` (Socket Statistics) command.
1. Open your terminal application or connect to the server via SSH.
2. Method 1: The Master Socket Dump (`ss`):
* This is the mathematically superior method for extracting active port telemetry.
* The Syntax: `sudo ss -tuln`
* -t: Show TCP ports.
* -u: Show UDP ports.
* -l: Show only listening sockets (ports actively waiting for an incoming connection).
* -n: Show numeric addresses (prevents the OS from wasting CPU cycles attempting to resolve DNS names).
* Type exactly:
sudo ss -tuln
* Press Enter.
* The Diagnostic Dump: The terminal will output a precise mathematical grid. Look at the column labelled Local Address:Port. An entry like `0.0.0.0:22` indicates the SSH daemon is actively listening on Port 22 across all network interfaces.
3. Method 2: The Process Identification Vector (`lsof`):
* If the `ss` command reveals that Port `8080` is occupied, but you do not know which specific application is holding the socket, you must interrogate the file system using `lsof` (List Open Files).
* Type exactly (replacing 8080 with your target port):
sudo lsof -i :8080
* Press Enter.
* The Result: The output will explicitly name the rogue daemon (e.g., `java` or `node`) and its exact Process ID (PID), allowing you to execute a targeted `kill` command.
4. Method 3: The Uncomplicated Firewall Audit (`ufw`):
* Sometimes a port is actively listening internally, but the external firewall is mathematically blocking the packet routing.
* Type exactly:
sudo ufw status verbose
* Press Enter. This outputs the definitive list of ports the OS is allowed to expose to the external internet matrix.