| Interface | State | IP address | Received | Sent | Errors/Drops |
|---|---|---|---|---|---|
| lo | UNKNOWN | 127.0.0.1 | 12 GB | 12 GB | 0 |
| eth0 | Active | 203.0.113.10 | 842 GB | 532 GB | 0 |
ss -tulpn answers the single most useful security question there is: what on this machine is reachable from outside? The output is dense, it scrolls, and it needs re-reading every time. This page shows the same information laid out — the listening sockets with their port, protocol, bind address and the process behind each one, followed by the connections currently established.
The bind address is the field to read first, and the one most often missed. A service on 127.0.0.1 is reachable only from the machine itself; the same service on 0.0.0.0 is reachable from the entire internet unless a firewall rule says otherwise. Databases, caches, message brokers and administrative interfaces are the ones that end up exposed this way, usually because a default configuration was never changed.
Read this page next to the UFW page. The firewall tells you which ports are meant to be open; this one tells you what is actually listening. When those two disagree, this is the list that reflects reality.