+961 70 327 329 info@nemeritsolutions.com Mon - Fri, 9:00 - 18:00
5.0 customer rating

Free tool

Network Port Number Reference

Search the common TCP and UDP port numbers, what service uses each one, and whether it is safe to leave that port open to the internet.

Search by port number or by service name. The last column is the part that matters: whether that port is designed to face the internet, needs care before it does, or should never be reachable from outside your network.

92 ports listed

PortProtocolServiceWhat it doesInternet
80 TCP HTTP Unencrypted web traffic. Normally present only to redirect visitors to HTTPS. Public
443 TCP/UDP HTTPS, HTTP/3 Encrypted web traffic. UDP on 443 carries HTTP/3 over QUIC. Public
8080 TCP HTTP alternate Second web port, often a proxy, a development server or an admin panel. With care
8443 TCP HTTPS alternate Secondary HTTPS port, commonly a management interface. With care
8000 TCP HTTP development Development servers and application frameworks. Rarely meant to be public. Internal only
2082 TCP cPanel cPanel over plain HTTP. Use 2083 instead. Internal only
2083 TCP cPanel over TLS The cPanel control panel for a hosting account. With care
2086 TCP WHM WHM server administration over plain HTTP. Use 2087. Internal only
2087 TCP WHM over TLS Full server administration. Restrict to known addresses. With care
2095 TCP Webmail cPanel webmail over plain HTTP. Use 2096. Internal only
2096 TCP Webmail over TLS cPanel webmail, encrypted. Public
10000 TCP Webmin Linux server administration panel. A frequent target. Internal only
25 TCP SMTP Mail server to mail server delivery. Never use for sending from a client. Public
465 TCP SMTPS Submitting mail over an implicit TLS connection. Public
587 TCP SMTP submission The correct port for a mail client to send through, with STARTTLS. Public
110 TCP POP3 Collecting mail, unencrypted. Passwords travel in clear text. Internal only
995 TCP POP3S Collecting mail over TLS. Public
143 TCP IMAP Reading mail on the server, unencrypted unless STARTTLS is enforced. With care
993 TCP IMAPS Reading mail on the server over TLS. The normal choice. Public
4190 TCP ManageSieve Server side mail filtering rules. With care
20 TCP FTP data The data channel for active mode FTP. Internal only
21 TCP FTP control Credentials and file contents travel unencrypted. Use SFTP or FTPS. Internal only
22 TCP SSH, SFTP, SCP Encrypted shell and file transfer. Use keys, never passwords. With care
69 UDP TFTP No authentication at all. Used for switch and phone firmware on a LAN only. Internal only
989 TCP FTPS data FTP data channel wrapped in TLS. With care
990 TCP FTPS control FTP control channel wrapped in TLS. With care
445 TCP SMB, Windows shares Windows file sharing. Exposing this to the internet is how ransomware spreads. Internal only
139 TCP NetBIOS session Legacy Windows file sharing. Internal networks only. Internal only
137 UDP NetBIOS name Legacy Windows name resolution. Internal only
138 UDP NetBIOS datagram Legacy Windows browsing and announcements. Internal only
2049 TCP/UDP NFS Unix network file system. Trusts the network it runs on. Internal only
873 TCP rsync File synchronisation. Often left open with no authentication. Internal only
548 TCP AFP Apple file sharing, largely replaced by SMB. Internal only
23 TCP Telnet Entirely unencrypted remote shell. Should not be running anywhere. Internal only
3389 TCP/UDP RDP Windows remote desktop. The single most attacked port on the internet. Use a VPN. Internal only
5900 TCP VNC Remote screen access, often with weak or no authentication. Internal only
5938 TCP TeamViewer Outbound connection to the TeamViewer service. Public
3283 TCP/UDP Apple Remote Desktop Apple remote management reporting channel. Internal only
8291 TCP MikroTik Winbox MikroTik router management. Restrict to the LAN or a VPN. Internal only
8728 TCP MikroTik API RouterOS API, unencrypted. Internal only
8729 TCP MikroTik API TLS RouterOS API over TLS. With care
500 UDP IKE, IPsec Key exchange for IPsec VPN tunnels. Public
4500 UDP IPsec NAT traversal IPsec where one end sits behind NAT. Public
1194 UDP OpenVPN The OpenVPN default. TCP 443 is often used to pass through restrictive networks. Public
51820 UDP WireGuard Modern VPN. Silent to anyone without a valid key. Public
1723 TCP PPTP Obsolete and broken encryption. Do not deploy it. Internal only
1701 UDP L2TP Tunnelling, used with IPsec for the encryption it lacks. Public
3306 TCP MySQL, MariaDB Should listen on localhost or the internal network only. Internal only
5432 TCP PostgreSQL Internal use only. Never expose a database to the internet. Internal only
1433 TCP Microsoft SQL Server Internal only. A long history of worms targeting it. Internal only
1521 TCP Oracle Oracle database listener. Internal only. Internal only
27017 TCP MongoDB Historically shipped with no authentication. Thousands were ransomed because of it. Internal only
6379 TCP Redis No authentication by default and trivially abused to run commands. Internal only
11211 TCP/UDP Memcached No authentication, and on UDP it has been used for enormous amplification attacks. Internal only
9200 TCP Elasticsearch A full HTTP API over your data. Internal only. Internal only
5984 TCP CouchDB HTTP database interface. Internal only. Internal only
53 TCP/UDP DNS Name resolution. UDP for queries, TCP for large answers and zone transfers. With care
853 TCP DNS over TLS Encrypted DNS queries. Public
67 UDP DHCP server Hands out addresses. Local network only by design. Internal only
68 UDP DHCP client The client side of address assignment. Internal only
123 UDP NTP Time synchronisation. Has been abused for amplification attacks. With care
161 UDP SNMP Device monitoring. Version 1 and 2c send the community string in clear text. Internal only
162 UDP SNMP trap Alerts sent from devices to a monitoring server. Internal only
389 TCP LDAP Directory lookups, unencrypted. Internal only. Internal only
636 TCP LDAPS Directory lookups over TLS. With care
88 TCP/UDP Kerberos Windows domain authentication. Internal only
514 UDP Syslog Log collection. Unauthenticated and easily spoofed. Internal only
6514 TCP Syslog over TLS Encrypted log transport. With care
179 TCP BGP Routing between networks. Peers only. Internal only
1812 UDP RADIUS auth Authentication for Wi-Fi, VPN and hotspot users. Internal only
1813 UDP RADIUS accounting Session accounting records. Internal only
5353 UDP mDNS, Bonjour Local device discovery. Should never cross a router. Internal only
1900 UDP SSDP, UPnP Device discovery. A well known amplification source. Disable on the WAN. Internal only
5060 TCP/UDP SIP Call signalling, unencrypted. Scanned constantly for toll fraud. Internal only
5061 TCP SIP over TLS Encrypted call signalling. With care
10000-20000 UDP RTP media The audio itself. A wide range, which is why VoIP and strict firewalls argue. With care
4569 UDP IAX2 Asterisk to Asterisk trunking. With care
554 TCP/UDP RTSP Camera video streams. Frequently exposed with default credentials. Internal only
37777 TCP Dahua Dahua recorder and camera protocol. Internal only
8000 TCP Hikvision Hikvision service port. Use a VPN rather than forwarding it. Internal only
34567 TCP XMEye, generic NVR Common on inexpensive recorders, with a poor security record. Internal only
3702 UDP ONVIF discovery How recorders find cameras on the network. Internal only
502 TCP Modbus Industrial and building control. No authentication whatsoever. Internal only
3000 TCP Node, Grafana Common development server and Grafana default. With care
5000 TCP Flask, Docker registry Python development server and private registry default. Internal only
9000 TCP PHP-FPM, Portainer PHP process manager, which must never be public, and Portainer. Internal only
2375 TCP Docker API Unencrypted Docker control. Exposing it hands over the whole host. Internal only
2376 TCP Docker API over TLS Docker control with certificate authentication. Internal only
6443 TCP Kubernetes API Cluster control plane. With care
9090 TCP Prometheus, Cockpit Metrics collection and Linux web administration. Internal only
8086 TCP InfluxDB Time series database API. Internal only
25565 TCP Minecraft Game server default, listed because it comes up constantly in home networks. With care

The three ports that cause most breaches

If you only check three things on a firewall, check that 3389, 445 and 22 are not open to the whole internet. Remote desktop on 3389 is scanned continuously by automated tools that try common passwords all day, and it is the most frequent way ransomware reaches a business network. Windows file sharing on 445 is how that ransomware then spreads once it is inside. SSH on 22 is safer because it can be configured properly, but only if password logins are switched off and keys are used instead.

None of these need to be public. A VPN puts all three behind a single encrypted door that does not answer strangers, and it is the one change that removes the largest amount of risk for the least effort.

Databases are never a public service

Every database port in the list above is marked internal only, and that is not caution. MongoDB, Redis and Memcached all shipped for years with no authentication enabled by default, and tens of thousands of them were found, emptied and held for ransom by people doing nothing more sophisticated than scanning the internet. A database should listen on localhost or on a private address that only the application server can reach. If a hosting provider tells you otherwise, that is worth questioning.

Cameras and recorders deserve special suspicion

CCTV equipment is the worst offender in most buildings. Recorders are routinely installed with the port forwarded straight through the router so the owner can watch from a phone, often with the factory password still set and firmware that has never been updated. Public search engines index these devices, which means anybody can find them. Remote viewing is reasonable to want. Do it through a VPN or the manufacturer's cloud relay rather than by opening the recorder to everyone.

A closed port tells an attacker less than a filtered one

There is a difference between a port that refuses a connection and one that never answers. A refusal confirms there is a live host at that address. Silence tells a scanner nothing, which is why a firewall should drop unwanted traffic rather than reject it. It is a small configuration detail that makes your network considerably less interesting to automated scanning.

Get in touch

Streamline your technology with IT support you can reach

Tell us what is slowing you down. We will come back with a plan and a price no obligation.