Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Stop assuming local ports are actually bound to everything
🧩 The Challenge
You finally deploy your fancy new app, run a quick check, and see a process listed but curl returns connection refused. It turns out you bound the service to 127.0.0.1 instead of 0.0.0.0, and you spent an hour staring at iptables rules that were totally fine.
💡 The Fix
Use the numeric and process flags with the socket statistics tool to verify the exact interface a process is listening on, not just the port number. It saves you from checking the wrong log files for thirty minutes.
ss -tulpn | grep LISTEN
⚙️ Why It Works
By forcing numeric output and showing the process, you bypass the annoying reverse DNS lookups and see exactly which PID owns the socket and what interface is attached to it. It kills the guesswork when you have multiple instances running on similar ports.
🚀 Pro-Tip: Pipe it into awk if you just want the local port and PID to quickly kill that runaway process hogging the port.
Linux Tips & Tricks | © ngelinux.com | 10/8/2026
