Skip to content
Article

What Is a Port? Port Numbers and Port Security

A port is the number that tells a device which service incoming traffic belongs to. We cover port ranges, common ports and the risk of open ports.

Oğuzhan Gerçek··7 min read
What Is a Port? Port Numbers and Port Security

Short answer: In computer networking, a port is a number that identifies which application on a device incoming traffic is meant for. The IP address gets a packet to the right device; the port number decides whether the web server, the mail server or remote desktop on that device answers it. Port numbers run from 0 to 65535, and IANA keeps the registry of assignments such as 443 for HTTPS and 22 for SSH. The basic security rule is to expose only the ports that are genuinely needed.

What is a port?

In IT, "port" means two different things: the physical socket on a device, and the port number in network traffic. This article is about the second.

A port is a transport-layer concept. RFC 9293 (August 2022), the current specification of TCP, says TCP uses port numbers to identify application services and to multiplex distinct flows between hosts. The source and destination port fields in the TCP header are 16 bits each, which allows 65,536 different numbers, from 0 to 65535. UDP's 1980 specification, RFC 768, also puts a source and a destination port field in its header. UDP is a leaner protocol that does not guarantee delivery.

IP address vs port

If the IP address is a building's street address, the port is the apartment number: the address gets the packet to the right device, and the port says which application on that device receives it. The two are written together as 192.0.2.10:443, with the number after the colon being the port.

In Oracle's Java documentation, the combination of an IP address and a port number is an endpoint, and every TCP connection can be uniquely identified by its two endpoints. RFC 9293 puts it as a connection being defined by a pair of sockets. That is why thousands of users can connect to port 443 on the same server at once: each connection differs in the client's address or port.

Port number ranges

RFC 6335 (August 2011) divides port numbers into three ranges:

  • System ports (0–1023): Also known as well-known ports, assigned by IANA. HTTP, HTTPS, SSH and DNS live here.
  • User ports (1024–49151): Also known as registered ports, also assigned by IANA.
  • Dynamic ports (49152–65535): Also known as private or ephemeral ports, and never assigned to any service.

The dynamic range is used on the client side: your browser connects to a server's port 443 from a temporary port the operating system picks at that moment. Operating systems do not all use the range the same way. To comply with IANA recommendations, Microsoft changed the default dynamic range to 49152–65535 in Windows Vista and Windows Server 2008, while the Linux kernel's default local port range is 32768–60999.

Common port numbers

These are the numbers you meet most often in the IANA port registry:

  • 20 and 21: FTP (file transfer; 20 for data, 21 for control)
  • 22: SSH
  • 23: Telnet
  • 25: SMTP (mail transfer)
  • 53: DNS
  • 80: HTTP
  • 443: HTTPS (HTTP over TLS)
  • 445: SMB (registered as microsoft-ds)
  • 1433: Microsoft SQL Server
  • 3306: MySQL
  • 3389: Remote Desktop, RDP (registered as ms-wbt-server)
  • 5432: PostgreSQL

Numbers are registered separately for TCP and UDP; DNS's port 53, for example, is registered for both. These are defaults, not rules: Microsoft documents how to change the Remote Desktop listening port from its default of 3389.

A physical port is not a network port

The Ethernet socket on a switch, modem or computer is also called a port, but it is a physical connection point. A TCP/UDP port is a number in software that identifies a service. The "port security" feature on switches also concerns physical ports. We cover the physical side of the network in our LAN article.

How does a server listen on a port?

When server software starts, it opens a specific port and waits for connections arriving on it; this is called listening. A web server listens on 443 and an SSH server on 22. We explain how servers work in general in our server article.

To see which ports a machine is listening on, use ss -tuln on Linux or netstat -ano on Windows. With these options, ss lists listening TCP and UDP sockets in numeric form, and netstat shows listening ports and connections together with the owning process ID (PID).

Open port risk and port security

Every port open to the internet is a door an attacker can try. These doors are found by port scanning: NIST SP 800-115 (September 2008) describes using a port scanner to identify the ports and services running on active hosts as a testing technique. In Nmap's classification, an open port means an application is accepting connections, and a closed port means no application is listening. A filtered port means packet filtering stops the probes from reaching the port.

The core principle is to open no port that is not needed:

  • Deny by default: NIST SP 800-41 Rev. 1 (September 2009) recommends blocking all inbound and outbound traffic that has not been expressly permitted. Firewall rules are therefore written around the question "what do I need to open?"
  • Remove unneeded services: NIST SP 800-123 (July 2008) calls for removing services and network protocols a server does not need. No listening service means no open port.
  • Do not expose remote access directly: According to CISA's ransomware guide, threat actors often gain initial access through exposed and poorly secured remote services. The guide recommends limiting the use of RDP and blocking TCP port 445 inbound and outbound to cut off external SMB access.
  • Do not mistake a port change for protection: Moving SSH from 22 to another port does not hide it; a tool that scans every port will still find it. As NIST SP 800-123 puts it, system security should not depend on the secrecy of its components.
  • Scan regularly: CISA recommends regular vulnerability scanning, especially of internet-facing devices. We cover regular scanning of externally visible ports in our vulnerability scan service.

Where a port has to stay open, as with a website, protection comes from layers placed in front of it: a WAF that inspects HTTP traffic (our WAF article) or a reverse proxy that answers requests on the server's behalf (our proxy article). Whether an open port can actually be exploited is what a penetration test shows. Port and firewall policy fall under our network security service.

Frequently asked questions

What does port mean in networking? A number that identifies which application on a device incoming network traffic belongs to.

What is an IP and port? An IP address and a port number written together, such as 192.0.2.10:443. The IP address points to the device and the port number to the service on it.

How many ports are there? TCP and UDP port numbers run from 0 to 65535, so each protocol has 65,536 port numbers.

Are open ports dangerous? An open port means an application behind it is accepting connections. That is fine if the service is needed and kept up to date; if it is not needed, or only used from the internal network, it should be closed to the internet.

What is port forwarding? A rule on a router or firewall that makes a server on the local network reachable from the internet: traffic arriving on a given port from outside is forwarded to a device inside. Every opened port adds attack surface, so it should only be used when necessary.

What are ports 80 and 443? Port 80 is for unencrypted web traffic (HTTP). Port 443 is used for web traffic encrypted with TLS (HTTPS).

Sources