Checking Network Connections: ss and nmcli Explained

Checking Network Connections: ss and nmcli Explained

Modern Linux network troubleshooting and configuration usually comes down to two tools: ss for inspecting the current state of connections and listening sockets, and nmcli for configuring and querying NetworkManager, the connection management service most desktop and many server distributions use by default. This guide covers both.

ss: socket statistics

ss replaced the older netstat as the standard tool for inspecting sockets on Linux, reading connection data directly from the kernel rather than parsing /proc files, which makes it noticeably faster on systems with many open connections.

ss -tuln

This is the most commonly reached-for ss invocation: -t for TCP, -u for UDP, -l for listening sockets only, -n for numeric output (skip resolving hostnames and service names, which is both faster and clearer for scripting).

Netid  State   Local Address:Port    Peer Address:Port
tcp    LISTEN  0.0.0.0:22             0.0.0.0:*
tcp    LISTEN  127.0.0.1:5432         0.0.0.0:*

Finding what’s listening on a specific port

ss -tlnp | grep :80

Adding -p shows the process name and PID that owns each socket, typically requiring sudo to see full details for sockets belonging to other users. This is the standard way to answer “is something already using this port” before starting a service that needs it, or “what is this open port for” when auditing a system.

Viewing all active connections, not just listening sockets

ss -tp

Without -l, ss shows established and other active connections rather than restricting to listening sockets, useful for seeing what remote addresses a system is currently talking to.

ss -s

-s prints a summary: total socket counts by state and protocol, a quick way to get an overview before drilling into specifics.

nmcli: NetworkManager’s command-line interface

Where ss reports state, nmcli configures it. NetworkManager is the connection management service used by most desktop distributions and many servers, handling Wi-Fi, wired connections, VPNs, and more, and nmcli is how you drive it without a graphical interface.

Checking device and connection status

nmcli device status
DEVICE  TYPE      STATE       CONNECTION
eth0    ethernet  connected   Wired connection 1
wlan0   wifi      disconnected --
nmcli device show eth0

device show gives full detail on a specific device: IP address, gateway, DNS servers, and more. device status gives a compact overview across all devices, a good first check when diagnosing “why is this machine not on the network.”

Connecting to Wi-Fi

nmcli device wifi list
nmcli device wifi connect "NetworkName" password "thepassword"

Once connected successfully, NetworkManager saves the connection profile automatically, so future reconnection to the same network happens without re-entering the password.

nmcli connection show                       # list all saved connection profiles
nmcli connection show "NetworkName"          # detailed settings for one profile
nmcli connection delete "NetworkName"        # remove a saved profile

Setting a static IP

nmcli connection modify "Wired connection 1" \
  ipv4.addresses 192.168.1.50/24 \
  ipv4.gateway 192.168.1.1 \
  ipv4.dns "8.8.8.8,8.8.4.4" \
  ipv4.method manual

nmcli connection up "Wired connection 1"

ipv4.method manual switches the connection from DHCP (the default, automatic addressing) to a manually specified static configuration. connection up reapplies the profile with the new settings.

Bringing an interface up or down

nmcli device disconnect eth0
nmcli device connect eth0

Useful for resetting a connection without physically unplugging anything, or for temporarily taking an interface offline during troubleshooting.

Combining both: a realistic troubleshooting flow

A common real scenario: a service will not start because “address already in use.”

# What's using port 5432?
ss -tlnp | grep :5432

# Confirm the machine's own network config isn't the problem
nmcli device status
nmcli device show eth0

ss answers whether the port is genuinely occupied and by what. nmcli answers whether the network interface itself is configured and connected correctly. Between the two, most everyday connectivity and port-conflict troubleshooting on a modern Linux desktop or server is covered without needing a graphical tool.

Frequently Asked Questions

What is the difference between ss and netstat?

netstat is the older, traditional tool for inspecting sockets and connections, but it has been deprecated on Linux in favor of ss for years, and many minimal distributions no longer install it by default. ss (socket statistics) reads connection information directly from kernel data structures rather than parsing /proc files the way netstat does, which makes it significantly faster, especially on systems with a large number of open connections. The command-line flags are similar enough between the two that switching from netstat habits to ss is a fairly small adjustment, and ss is the tool worth learning going forward.

How do I see what is listening on a specific port?

Use ss -tlnp | grep :PORT, substituting the port number you care about, for example ss -tlnp | grep :80 to check what is listening on port 80. -t filters to TCP sockets, -l shows only listening sockets, -n shows numeric addresses and ports instead of resolving names, and -p shows the process name and PID that owns each socket (this last flag typically requires root or sudo to see process details for sockets owned by other users).

What does nmcli do that ss cannot?

ss inspects the current state of network connections and listening sockets, it does not configure anything. nmcli is a command-line interface to NetworkManager, the connection management service used by most desktop and many server Linux distributions, and it handles configuration: connecting to Wi-Fi networks, setting static IP addresses, managing VPN connections, and bringing network interfaces up or down. The two tools answer different questions: ss answers “what is currently connected or listening,” nmcli answers “how is my network configured, and let me change it.”

How do I connect to a Wi-Fi network from the command line with nmcli?

First list available networks with nmcli device wifi list, then connect with nmcli device wifi connect “NetworkName” password “thepassword”. NetworkManager saves the connection profile after a successful connection, so it reconnects automatically in range in the future without needing the password re-entered. To see saved connection profiles, use nmcli connection show, and to remove one, nmcli connection delete “NetworkName”.

How do I check my current IP address and network configuration with nmcli?

nmcli device show shows detailed configuration for every network device, including IP address, gateway, DNS servers, and connection state. For a more compact summary, nmcli device status lists each device with its type, current state (connected, disconnected, unavailable), and the connection profile in use. Both are useful starting points for network troubleshooting, confirming basics like whether an interface has an IP address at all before investigating further.

How do I find which process is using a specific network connection?

ss -tp shows all TCP connections along with the process name and PID that owns each one (root privileges are typically needed to see this for connections owned by other users). Combine with grep to narrow down to a specific port or address, such as ss -tp | grep :443 to see what is holding open connections on port 443. This is the standard way to answer “what program is talking to this remote address” or “why is this port already in use” when trying to start a service that fails because the port is occupied.