TCP, UDP & ports
An IP address gets a packet to the right machine. But a server runs lots of programs at once: SSH, a website, a database. The port number gets the packet to the right program. And whether that program uses TCP or UDP decides how careful the conversation is. This lesson is about what happens after the address part works.
You will learn
- Ports, sockets, and which numbers mean what
- TCP vs UDP: a careful phone call vs a postcard
- The three-way handshake, seen with
tcpdump - Reading
ss: who's listening, who's connected - "Connection refused" vs "timed out", and what each one tells you
Ports: one address, many programs
A port is a number from 0 to 65535 that's added to an address: 192.168.1.50:22 is SSH on the club server, 192.168.1.50:80 is its website. A program that waits for connections listens on a port. Every conversation is identified by both ends, called a socket pair:
192.168.1.23:51544 ⇄ 192.168.1.50:22
your laptop, a random port the server, the SSH port
- Well-known ports (0–1023) belong to standard services: 22 SSH, 53 DNS, 80 HTTP, 443 HTTPS. On Linux, only root can listen on them.
- Ephemeral ports are the random high numbers your side uses when it starts a connection. Linux picks them from
/proc/sys/net/ipv4/ip_local_port_range(32768–60999). - The names live in
/etc/services. That's how tools turn80intohttp. Look one up withgetent services ssh.
TCP vs UDP
| What | TCP | UDP |
|---|---|---|
| Like… | a phone call: say hello first, confirm everything | a postcard: write it, send it, hope |
| Before sending | a handshake sets up a connection | nothing: just send |
| Lost data | noticed and sent again, in the right order | simply lost (the app can deal with it if it cares) |
| Speed | a bit slower to start | no waiting at all |
| Used for | web pages, SSH, email, databases | DNS lookups, time sync (NTP), video calls, games, HTTP/3 |
The three-way handshake
Every TCP connection starts the same way:
- SYN: the client says "I'd like to talk" (and picks a starting sequence number).
- SYN-ACK: the server says "OK, me too" (if something's listening on that port).
- ACK: the client says "great". The connection is open, and data can flow.
Every piece of data is then acknowledged (ACK), and the connection ends with a FIN from each side. If you knock on a port where nothing listens, the machine answers the SYN with a RST (reset). In tcpdump, these show up as Flags [S], [S.], [.], [P.] (data), [F.] and [R].
Refused vs timed out
When a connection fails, how it fails tells you where to look:
| You see | What happened | Look at |
|---|---|---|
| Connection refused (fast) | The machine answered with RST: it's there, but nothing listens on that port | Is the service running? Is it on the right port? ss -tlnp |
| Timed out (slow) | No answer at all: a firewall dropped the SYN, or the machine is off or unreachable | Firewalls on the way, routing, is the host up? |
| No route to host | A router or firewall said "can't get there from here" | Routing (lesson 2), or a firewall that rejects |
nc -zv HOST PORT (netcat) is the quickest test: -z just knocks without sending data, -v says what happened.
What's listening on a fresh server
ss works the same on both families, but what they run out of the box differs:
| What | Rocky / RHEL | Ubuntu / Debian |
|---|---|---|
| TCP listeners | sudo ss -tlnp same on both: SSH on 22 (plus anything you installed) | |
| UDP sockets | sudo ss -ulnp: chronyd (time sync) on 127.0.0.1:323 | sudo ss -ulnp: systemd-resolved (DNS) on 127.0.0.53:53, and the DHCP client on :68 |
| tcpdump | sudo dnf install tcpdump | preinstalled |
| netcat flavour | ncat from Nmap (package nmap-ncat) | OpenBSD nc (preinstalled) |
The ss letters: -t TCP, -u UDP, -l listening only, -n numbers instead of names, -p show the program (needs sudo), -a everything. Without -l you see live connections instead (ESTAB).
Try it: listen in on the club server 🔌
The club website is running. Find every open door on the server, watch someone visit the site packet by packet, and learn to tell a closed door from a guarded one.
Quick check
1. nc -zv 10.0.0.5 5432 waits for a long time and then says "timed out". Most likely?
✓ A stopped service gives a quick "refused" (RST). Silence means something swallowed the packet.
2. Why does DNS use UDP for normal lookups?
✓ If the reply gets lost, the resolver simply asks again. (Big DNS answers do switch to TCP.)
3. In ss -tn you see 192.168.1.50:22 ⇄ 192.168.1.23:51544. What's 51544?
✓ The server listens on 22; the client side uses a random high port.