An IP address gets traffic to the right machine; a port number gets it to the right program on that machine. Port 443 reaches the web server, 3306 reaches MySQL, 3389 reaches Remote Desktop. Knowing the common ports by heart makes firewall rules, troubleshooting and security reviews much faster, and helps you spot when something is exposed that should not be.
Ports, TCP and UDP in brief
Port numbers run from 0 to 65535 and are grouped into three ranges, as maintained by IANA:
- 0–1023: well-known ports, for core services like HTTP and SSH. On Linux and macOS, binding to these traditionally requires administrator rights.
- 1024–49151: registered ports, assigned to specific applications such as databases.
- 49152–65535: dynamic or ephemeral ports, used temporarily by clients for outgoing connections.
Ports exist separately for two transport protocols. TCP sets up a connection and guarantees ordered, complete delivery; most services use it. UDP just sends packets with no handshake, which suits DNS lookups, voice, video and some VPNs. A firewall rule must specify the right protocol: allowing TCP 53 does not allow UDP 53.
Port numbers are conventions, not guarantees. Any service can run on any port; the numbers below are the defaults.
Web
| Port | Protocol | Service | Notes |
|---|---|---|---|
| 80 | TCP | HTTP | Unencrypted web; keep open only to redirect to HTTPS |
| 443 | TCP, UDP | HTTPS | UDP 443 carries HTTP/3 (QUIC) |
| 8080, 8443 | TCP | Alternative HTTP/HTTPS | Common for app servers, proxies and admin panels |
| Port | Protocol | Service | Notes |
|---|---|---|---|
| 25 | TCP | SMTP | Server-to-server mail delivery; many ISPs block it outbound |
| 587 | TCP | SMTP submission | Email clients sending mail, upgraded with STARTTLS |
| 465 | TCP | SMTP submission over TLS | Encrypted from the start (implicit TLS) |
| 143 / 993 | TCP | IMAP / IMAPS | Reading mail; prefer 993 (encrypted) |
| 110 / 995 | TCP | POP3 / POP3S | Older download-and-delete mail access; prefer 995 |
If a staff member's email client cannot send, check it is using 587 or 465 with authentication rather than 25.
Remote access and file transfer
| Port | Protocol | Service | Notes |
|---|---|---|---|
| 22 | TCP | SSH, SFTP | Secure shell and secure file transfer |
| 21 (and 20) | TCP | FTP | Sends passwords in plain text; replace with SFTP |
| 23 | TCP | Telnet | Unencrypted; should be disabled everywhere |
| 3389 | TCP, UDP | Remote Desktop (RDP) | Frequently attacked; never expose directly |
| 5900 | TCP | VNC | Remote screen sharing; restrict tightly |
Network infrastructure
| Port | Protocol | Service | Notes |
|---|---|---|---|
| 53 | UDP, TCP | DNS | UDP for most queries; TCP for large responses and zone transfers |
| 67 / 68 | UDP | DHCP | Server / client |
| 123 | UDP | NTP | Time synchronization; important for logs and certificates |
| 161 / 162 | UDP | SNMP / SNMP traps | Device monitoring; use SNMPv3 |
| 389 / 636 | TCP | LDAP / LDAPS | Directory services such as Active Directory |
| 445 | TCP | SMB | Windows file sharing; never expose to the internet |
Databases and caches
| Port | Service |
|---|---|
| 3306 | MySQL and MariaDB |
| 5432 | PostgreSQL |
| 1433 | Microsoft SQL Server |
| 1521 | Oracle Database listener |
| 27017 | MongoDB |
| 6379 | Redis |
All of these use TCP. None should be reachable from the whole internet. Databases belong on private networks, with access from application servers only, and admins connecting through a VPN or SSH tunnel.
VPNs
| Port | Protocol | Service |
|---|---|---|
| 500, 4500 | UDP | IPsec (IKE and NAT traversal) |
| 1194 | UDP (or TCP) | OpenVPN default |
| 51820 | UDP | WireGuard (common default) |
| 443 | TCP | Many SSL VPN products |
Hosting control panels and admin interfaces
Web hosting servers often run management panels on their own ports. These are worth recognizing because they give full control of the server and are popular targets for password guessing:
| Port | Service |
|---|---|
| 2082 / 2083 | cPanel (HTTP / HTTPS) |
| 2086 / 2087 | WHM, the cPanel server administration panel (HTTP / HTTPS) |
| 8443 | Plesk (HTTPS), also used by many other products |
| 10000 | Webmin |
| 9090 | Cockpit and various monitoring dashboards |
Where possible, restrict these to your office IP or a VPN, and always use the HTTPS port rather than the plain HTTP one. If your hosting provider manages the panel, ask how access is protected.
Outbound ports matter too
Most firewall discussions focus on inbound traffic, but outbound rules are also useful. Many small offices allow every outbound port, which means malware on a single laptop can send spam directly on port 25 or connect to a command server on any port it likes. A stricter outbound policy allows only what staff actually need, typically DNS (53) to your chosen resolvers, web (80 and 443), email submission (587 or 465, 993) and whatever your VPN or business applications require. Blocking outbound port 25 from everything except your mail server is a simple, high-value rule, and many internet providers already do it.
Checking which ports are open
To see what the internet can reach on your public address, test from outside your network with a port checker. Find your public address first with What Is My IP. On a server, list what is listening locally:
# Linux
sudo ss -tulpn
# Windows (PowerShell)
Get-NetTCPConnection -State Listen | Sort-Object LocalPort
A service listening locally is not necessarily reachable from outside; the firewall decides that. Compare the two views.
A sensible default firewall stance
- Block all inbound traffic by default.
- For a public web server, allow TCP 80 and 443 (and UDP 443 if you use HTTP/3).
- Allow SSH (22) or RDP (3389) only from specific admin IP addresses or via a VPN.
- Never expose database, cache, SMB or Telnet ports publicly.
- Review open ports after every new installation; many applications open admin interfaces on high ports by default.
Moving SSH from 22 to another port reduces log noise from automated scanners, but it is not a security control on its own. Keys, restricted source addresses and patching are what actually protect it.
Key takeaways
- Ports direct traffic to specific services; TCP and UDP ports are separate.
- Learn the core set: 22, 25, 53, 80, 443, 587, 993, 3306, 3389, 5432.
- Remote access, database and file-sharing ports should never be open to the whole internet.
- Check exposure from outside your network, not just from the server itself.