Thanks a lot.

I'll use a combination of A & B.  "netstat -an" will show all the ports
including those "listening", "established" but it's the "established"
ones that indicate the port is being used :

These have answered my question of how to differentiate
between a telnet & an ssh access to the server.

Lsof shows list of open files , but with lsof -i:80 you will see if port 80
is in use or not - not only tell you if it's in use, but it'll tell you
what's using it


'netstat -f inet' will show you all IPv4 ports in use; 'netstat -P tcp'
shows you all TCP sockets in use, regardless of address family. You could
probably cron it to run every few minutes, dump the output to a file, and
with a little grepping get a list of all ports used over the next few days


>From another machine use nmap and nmapfe
netstat -an | awk '$1~ /\*\./ { print $0 }'


