How the internet works · Lesson 4 · 30 min

TCP, UDP & ports

An IP address gets a packet to the right machine. But a server runs lots of programs at once: SSH, a website, a database. The port number gets the packet to the right program. And whether that program uses TCP or UDP decides how careful the conversation is. This lesson is about what happens after the address part works.

You will learn

  • Ports, sockets, and which numbers mean what
  • TCP vs UDP: a careful phone call vs a postcard
  • The three-way handshake, seen with tcpdump
  • Reading ss: who's listening, who's connected
  • "Connection refused" vs "timed out", and what each one tells you

Ports: one address, many programs

A port is a number from 0 to 65535 that's added to an address: 192.168.1.50:22 is SSH on the club server, 192.168.1.50:80 is its website. A program that waits for connections listens on a port. Every conversation is identified by both ends, called a socket pair:

192.168.1.23:51544  ⇄  192.168.1.50:22
  your laptop, a random port    the server, the SSH port

TCP vs UDP

WhatTCPUDP
Like…a phone call: say hello first, confirm everythinga postcard: write it, send it, hope
Before sendinga handshake sets up a connectionnothing: just send
Lost datanoticed and sent again, in the right ordersimply lost (the app can deal with it if it cares)
Speeda bit slower to startno waiting at all
Used forweb pages, SSH, email, databasesDNS lookups, time sync (NTP), video calls, games, HTTP/3

The three-way handshake

Every TCP connection starts the same way:

  1. SYN: the client says "I'd like to talk" (and picks a starting sequence number).
  2. SYN-ACK: the server says "OK, me too" (if something's listening on that port).
  3. ACK: the client says "great". The connection is open, and data can flow.

Every piece of data is then acknowledged (ACK), and the connection ends with a FIN from each side. If you knock on a port where nothing listens, the machine answers the SYN with a RST (reset). In tcpdump, these show up as Flags [S], [S.], [.], [P.] (data), [F.] and [R].

Refused vs timed out

When a connection fails, how it fails tells you where to look:

You seeWhat happenedLook at
Connection refused (fast)The machine answered with RST: it's there, but nothing listens on that portIs the service running? Is it on the right port? ss -tlnp
Timed out (slow)No answer at all: a firewall dropped the SYN, or the machine is off or unreachableFirewalls on the way, routing, is the host up?
No route to hostA router or firewall said "can't get there from here"Routing (lesson 2), or a firewall that rejects

nc -zv HOST PORT (netcat) is the quickest test: -z just knocks without sending data, -v says what happened.

What's listening on a fresh server

ss works the same on both families, but what they run out of the box differs:

WhatRocky / RHELUbuntu / Debian
TCP listenerssudo ss -tlnp same on both: SSH on 22 (plus anything you installed)
UDP socketssudo ss -ulnp: chronyd (time sync) on 127.0.0.1:323sudo ss -ulnp: systemd-resolved (DNS) on 127.0.0.53:53, and the DHCP client on :68
tcpdumpsudo dnf install tcpdumppreinstalled
netcat flavourncat from Nmap (package nmap-ncat)OpenBSD nc (preinstalled)

The ss letters: -t TCP, -u UDP, -l listening only, -n numbers instead of names, -p show the program (needs sudo), -a everything. Without -l you see live connections instead (ESTAB).

Try it: listen in on the club server 🔌

The club website is running. Find every open door on the server, watch someone visit the site packet by packet, and learn to tell a closed door from a guarded one.

Quick check

1. nc -zv 10.0.0.5 5432 waits for a long time and then says "timed out". Most likely?

2. Why does DNS use UDP for normal lookups?

3. In ss -tn you see 192.168.1.50:22 ⇄ 192.168.1.23:51544. What's 51544?

Finished the missions and the quiz? Mark it done to track your progress.