Blog

Networking articles

Common Network Ports Every IT Admin Should Know

A reference to common ports for web, email, remote access, databases and VPNs, with TCP/UDP details and which ones should never face the internet.

4 min read Networking

An IP address gets traffic to the right machine; a port number gets it to the right program on that machine. Port 443 reaches the web server, 3306 reaches MySQL, 3389 reaches Remote Desktop. Knowing the common ports by heart makes firewall rules, troubleshooting and security reviews much faster, and helps you spot when something is exposed that should not be.

Ports, TCP and UDP in brief

Port numbers run from 0 to 65535 and are grouped into three ranges, as maintained by IANA:

  • 0–1023: well-known ports, for core services like HTTP and SSH. On Linux and macOS, binding to these traditionally requires administrator rights.
  • 1024–49151: registered ports, assigned to specific applications such as databases.
  • 49152–65535: dynamic or ephemeral ports, used temporarily by clients for outgoing connections.

Ports exist separately for two transport protocols. TCP sets up a connection and guarantees ordered, complete delivery; most services use it. UDP just sends packets with no handshake, which suits DNS lookups, voice, video and some VPNs. A firewall rule must specify the right protocol: allowing TCP 53 does not allow UDP 53.

Port numbers are conventions, not guarantees. Any service can run on any port; the numbers below are the defaults.

Web

PortProtocolServiceNotes
80TCPHTTPUnencrypted web; keep open only to redirect to HTTPS
443TCP, UDPHTTPSUDP 443 carries HTTP/3 (QUIC)
8080, 8443TCPAlternative HTTP/HTTPSCommon for app servers, proxies and admin panels

Email

PortProtocolServiceNotes
25TCPSMTPServer-to-server mail delivery; many ISPs block it outbound
587TCPSMTP submissionEmail clients sending mail, upgraded with STARTTLS
465TCPSMTP submission over TLSEncrypted from the start (implicit TLS)
143 / 993TCPIMAP / IMAPSReading mail; prefer 993 (encrypted)
110 / 995TCPPOP3 / POP3SOlder download-and-delete mail access; prefer 995

If a staff member's email client cannot send, check it is using 587 or 465 with authentication rather than 25.

Remote access and file transfer

PortProtocolServiceNotes
22TCPSSH, SFTPSecure shell and secure file transfer
21 (and 20)TCPFTPSends passwords in plain text; replace with SFTP
23TCPTelnetUnencrypted; should be disabled everywhere
3389TCP, UDPRemote Desktop (RDP)Frequently attacked; never expose directly
5900TCPVNCRemote screen sharing; restrict tightly

Network infrastructure

PortProtocolServiceNotes
53UDP, TCPDNSUDP for most queries; TCP for large responses and zone transfers
67 / 68UDPDHCPServer / client
123UDPNTPTime synchronization; important for logs and certificates
161 / 162UDPSNMP / SNMP trapsDevice monitoring; use SNMPv3
389 / 636TCPLDAP / LDAPSDirectory services such as Active Directory
445TCPSMBWindows file sharing; never expose to the internet

Databases and caches

PortService
3306MySQL and MariaDB
5432PostgreSQL
1433Microsoft SQL Server
1521Oracle Database listener
27017MongoDB
6379Redis

All of these use TCP. None should be reachable from the whole internet. Databases belong on private networks, with access from application servers only, and admins connecting through a VPN or SSH tunnel.

VPNs

PortProtocolService
500, 4500UDPIPsec (IKE and NAT traversal)
1194UDP (or TCP)OpenVPN default
51820UDPWireGuard (common default)
443TCPMany SSL VPN products

Hosting control panels and admin interfaces

Web hosting servers often run management panels on their own ports. These are worth recognizing because they give full control of the server and are popular targets for password guessing:

PortService
2082 / 2083cPanel (HTTP / HTTPS)
2086 / 2087WHM, the cPanel server administration panel (HTTP / HTTPS)
8443Plesk (HTTPS), also used by many other products
10000Webmin
9090Cockpit and various monitoring dashboards

Where possible, restrict these to your office IP or a VPN, and always use the HTTPS port rather than the plain HTTP one. If your hosting provider manages the panel, ask how access is protected.

Outbound ports matter too

Most firewall discussions focus on inbound traffic, but outbound rules are also useful. Many small offices allow every outbound port, which means malware on a single laptop can send spam directly on port 25 or connect to a command server on any port it likes. A stricter outbound policy allows only what staff actually need, typically DNS (53) to your chosen resolvers, web (80 and 443), email submission (587 or 465, 993) and whatever your VPN or business applications require. Blocking outbound port 25 from everything except your mail server is a simple, high-value rule, and many internet providers already do it.

Checking which ports are open

To see what the internet can reach on your public address, test from outside your network with a port checker. Find your public address first with What Is My IP. On a server, list what is listening locally:

# Linux
sudo ss -tulpn

# Windows (PowerShell)
Get-NetTCPConnection -State Listen | Sort-Object LocalPort

A service listening locally is not necessarily reachable from outside; the firewall decides that. Compare the two views.

A sensible default firewall stance

  • Block all inbound traffic by default.
  • For a public web server, allow TCP 80 and 443 (and UDP 443 if you use HTTP/3).
  • Allow SSH (22) or RDP (3389) only from specific admin IP addresses or via a VPN.
  • Never expose database, cache, SMB or Telnet ports publicly.
  • Review open ports after every new installation; many applications open admin interfaces on high ports by default.

Moving SSH from 22 to another port reduces log noise from automated scanners, but it is not a security control on its own. Keys, restricted source addresses and patching are what actually protect it.

Key takeaways

  • Ports direct traffic to specific services; TCP and UDP ports are separate.
  • Learn the core set: 22, 25, 53, 80, 443, 587, 993, 3306, 3389, 5432.
  • Remote access, database and file-sharing ports should never be open to the whole internet.
  • Check exposure from outside your network, not just from the server itself.

Need help with this?

Netifi helps businesses around the world with Networking. Tell us what you are working on.