Wood Chen

Analyzing TCP Connection Details and Possible Causes

0 comments80 views677 words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

How to check the number of TCP connections for the current process on linux

On Linux, you can use the following command to check the number of TCP connections for the current process:

ss -s

This command displays socket statistics for the current system, including the number of TCP connections. "ESTAB" indicates the number of established TCP connections.

If you only want to see detailed information about TCP connections, use the following command:

ss -t -a

This command lists details of all TCP connections, including local addresses, remote addresses, and states.

Note that you may need sufficient permissions to run these commands. On some systems, you may need to run them as an administrator (root) using sudo:

sudo ss -s
sudo ss -t -a

If you prefer using netstat, you can try the following command:

netstat -nat

This displays details of all TCP connections, including local addresses, remote addresses, and states. You may also need to run this command as an administrator.

-ash: ss: command not found

It looks like ss may not be installed on your system. You can try using netstat to view the current number of TCP connections and their details. Here is an example:

netstat -nat

This command displays details of all TCP connections, including local addresses, remote addresses, and states. Note that on some systems, you may need to run it as an administrator using sudo:

sudo netstat -nat

If netstat is also unavailable, you may need to install the relevant networking tools package. On Debian/Ubuntu-based systems, use the following commands:

sudo apt-get update
sudo apt-get install net-tools

On Red Hat/CentOS-based systems, use the following command:

sudo yum install net-tools

Once installed, try running netstat again to view TCP connection information.

tcp 0 1296 172.18.0.1:22 172.18.0.3:34218 ESTABLISHED — I see this entry. Why are there so many TCP connections?

This entry shows information about an established TCP connection. Let's break it down:

  • tcp: Indicates that this is a TCP connection.
  • 0: A status flag for the local socket, usually not important.
  • 1296: The local port number, meaning the port used by the local host.
  • 172.18.0.1:22: The local address and port. Here, the local address is 172.18.0.1, and the port is 22 (the default port for SSH).
  • 172.18.0.3:34218: The remote address and port. Here, the remote address is 172.18.0.3, and the port is 34218.
  • ESTABLISHED: The connection state, indicating an established connection.

There are several possible reasons for having so many connections:

  1. Concurrent connections: The system is handling multiple concurrent SSH connections. This may be because multiple users are connecting to the system over SSH, or one user has multiple sessions.
  2. Idle SSH connections: Some connections may remain open because users did not explicitly close them after logging in. They may have left their terminal sessions open instead of using an exit command to close them.
  3. Network applications: If your system runs network applications or services, these may create a large number of connections.

To learn more about where the connections come from, use netstat or other networking tools to view more connection details and identify which processes or users established them. For example:

netstat -anp | grep 172.18.0.1:22

This displays details related to the local SSH port, including process IDs (PIDs). You can then use ps to view details for a specific PID:

ps aux | grep 

This lets you identify the source of a particular connection.

Shouldn't 1296 be the connection count?

Sorry for the misunderstanding in my previous answer. You are right: 1296 is a file descriptor, not a connection count. A file descriptor is a numeric identifier the operating system uses to track open files and network connections.

In this context, 1296 is the file descriptor number. Each open file, socket, or other I/O resource is assigned a unique file descriptor. So 1296 here is simply a number that uniquely identifies this connection.

To check the number of TCP connections on the current system, use the following command:

netstat -n | grep -c ESTABLISHED

This displays the number of TCP connections currently in the ESTABLISHED state. If you want to view all TCP connections, not just established ones, you can omit the grep -c ESTABLISHED portion.

Last updated 2024-01-14

Related posts

Comments 0