Stop guessing which socket is hogging your ephemeral ports
Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Stop guessing which socket is hogging your ephemeral ports
🧩 The Challenge
Dealing with a service that suddenly stops accepting connections because it ran out of ports is the absolute worst. You spend twenty minutes poking around only to find out some zombie process is holding thousands of connections in a TIME_WAIT state.
💡 The Fix
Use the socket statistics utility to filter by the state and process ID so you can see exactly which application is being a port-hog. It saves you from having to dig through massive dumps of every single socket on the machine.
ss -tanp state time-wait | grep :80
⚙️ Why It Works
Since the kernel keeps connections in this state for a set timeout, listing them directly allows you to identify the culprit before you decide to go nuclear and restart the entire application stack.
🚀 Pro-Tip: Alias this to something like ‘ss-zombies’ so you don’t have to remember the flags when the pager goes off at 3 AM.
Linux Tips & Tricks | © ngelinux.com | 9/29/2026
