Networking · Concept · 10 min read

Port 1433, and Why SQL Server Is Rarely Only on 1433

Port 1433 is the answer to the question and rarely the answer to the problem. Named instances, the Browser service, the admin connection and Azure SQL each put a SQL Server connection somewhere else.

Written by Marko Ristic, Editor Updated Sep 17, 2026
1433TCP, the default instance and nothing else by default
1434UDP for the Browser, TCP for the admin connection
11000the start of the Azure SQL range that Redirect also needs
2ports a named instance needs through a firewall: its own and UDP 1434
Short answer

Port 1433 is the TCP port the default instance of Microsoft SQL Server listens on. Named instances and SQL Server Express use dynamic ports chosen at startup, found through the SQL Server Browser on UDP 1434, which Microsoft suggests leaving stopped.

The dedicated administrator connection uses TCP 1434 when it is free. Azure SQL Database answers on 1433 at its gateway and, under the recommended Redirect policy, also needs ports 11000 to 11999. A firewall rule naming only 1433 covers one of those cases.

  • TCP 1433 is the default instance of the SQL Server Database Engine
  • Named instances and Express use dynamic ports unless you fix one
  • SQL Server Browser answers on UDP 1434; Microsoft suggests stopping it
  • Windows Firewall blocks 1433 by default
  • Azure SQL uses 1433 at the gateway and 11000 to 11999 with Redirect
On this page

What uses itWhat actually listens on port 1433

Microsoft's own documentation states it in one line: if enabled, the default instance of the SQL Server Database Engine listens on TCP port 1433. That is the whole of the default.

Only the default instance. A server can run several SQL Server instances side by side. One of them can be the default instance, reached by the server name alone, and that is the one on 1433.

Every other instance is a named instance, reached as server\instance, and Microsoft configures named instances for dynamic ports, which means they select an available port when the SQL Server service starts.

Express is a named instance too. SQL Server Express installs as a named instance by default, and Microsoft lists Express, Compact and named instances together as the ones that use dynamic ports.

The small accounting or practice management database on an office server is very often one of these, which is why "open port 1433" so often fails to fix the connection.

The error log says which port is in use. Microsoft points to the SQL Server error log as the place the Database Engine records the port it is actually listening on, and it is the information to collect before you configure a single rule. That is the fastest honest answer to the question, faster than guessing from the configuration.

It is TCP. Client connections and data access to the Database Engine on 1433 use TCP. The UDP port in this story is 1434, and it belongs to a different service, which is ordinary: a port number only means something together with its protocol.

The other portsThe ports that come with it

A SQL Server almost never uses one port, and the ones next to 1433 are where most firewall problems live.

UDP 1434, SQL Server Browser. The Browser service lets clients connect to instances that are not listening on 1433 without knowing their port number: the client asks the Browser which port an instance name is on, and connects there.

Microsoft's instruction for a server behind a firewall is to allow inbound UDP 1434 and the TCP port the instance uses. Its security advice runs the other way: to promote the most secure environment, leave the SQL Server Browser service stopped and configure clients to connect using the port number.

TCP 1434, the dedicated administrator connection. The DAC is the connection an administrator uses when SQL Server is unresponsive to normal connections.

SQL Server listens for it on TCP port 1434 if that port is available, or on a port assigned dynamically at startup, and the error log records which. By default the DAC listener accepts connections only locally; remote admin connections have to be turned on deliberately.

A fixed port for a named instance. When clients connect to a named instance through a firewall, Microsoft's guidance is to configure the Database Engine to listen on a specific port so the right port can be opened.

A dynamic port that changes at the next restart turns working firewall rules into an outage for every application that reads data from that instance.

Hiding an instance. The HideInstance flag stops the Browser from advertising an instance. Clients can still connect if they name the endpoint explicitly, for example tcp:server,5000, so hiding is a way to stay off a listing rather than a way to stay off the network.

Azure SQLAzure SQL, where 1433 is only the front door

Azure SQL Database keeps the number and changes what it means.

The gateway listens on 1433. Microsoft describes clients connecting to a gateway that has a public IP address and listens on port 1433, which then redirects or proxies the traffic to the right database cluster.

Redirect is the recommended policy, and it needs more ports. With the Redirect connection policy, clients connect directly to the node hosting the database, which Microsoft says reduces latency and improves throughput.

For that to work, the client must be allowed outbound to all Azure SQL IP addresses in the region on ports 11000 to 11999, as well as to the gateway on 1433. Microsoft suggests using the service tags for SQL to manage the address ranges.

Proxy keeps everything on 1433, at a cost. In the Proxy policy all connections go through the gateways, which Microsoft says increases latency and reduces throughput.

This is the rule that breaks after a migration. A company moves a database to Azure, opens outbound 1433 on the office firewall because that is the SQL port, and the application connects intermittently or not at all. The missing half is the 11000 to 11999 range.

EncryptionEncrypting what crosses port 1433

The port number says nothing about whether the session on it is encrypted, and SQL Server has changed how strictly that can be enforced.

SQL Server 2022 added strict encryption. To support TDS 8.0, SQL Server 2022 added strict as an additional connection encryption option in the drivers, set as Encrypt=strict, and it needs current driver versions for .NET, ODBC, OLE DB, JDBC, PHP and Python.

Strict removes the usual shortcut. Under strict encryption, Microsoft states that users cannot set TrustServerCertificate to true and accept any certificate the server offers; the client names the certificate it trusts instead. That shortcut is common in connection strings, and it is exactly what lets a man in the middle present his own certificate.

Strict is not free for every feature. Microsoft's TDS 8.0 documentation lists features where TDS 8.0 support introduces breaking changes, including linked servers and several replication types, so it is a change to test rather than a checkbox.

What to doWhat to do about port 1433 on a network you run

Keep it off the internet. Windows Firewall closes 1433 by default, and Microsoft notes that connections to the default instance over TCP/IP are not possible until it is opened.

The deliberate version of that is an inbound rule that allows access only from the application servers or the management subnet. Microsoft's own netsh example scopes the rule to the local subnet and the domain profile rather than to everyone.

Do not count on the port number to hide it. Microsoft is direct about this: some organizations change the SQL Server port to enhance security, but because a port scanner can query for open ports, changing the number is not considered a robust security measure.

Move it if a policy asks for it, and put the protection in the firewall rules, the scope of access and the authentication. The same argument applies to the RDP port, and for the same reason.

Stop the Browser if clients can be told the port. Fewer listening services, one less UDP port open, and no answer to anyone who asks the network what instances exist.

Fix the port on every named instance that crosses a firewall. A dynamic port is fine on a single server with a local application. It is not fine behind a rule that names a number.

Write the Azure ports into the change. If a database is moving to Azure SQL, the firewall change is 1433 to the gateway and 11000 to 11999 to the region, or the connection policy is set to Proxy on purpose.

Encrypt the session and remove TrustServerCertificate. On current drivers and SQL Server 2022, strict encryption is available; on anything older, at least stop accepting any certificate the server presents.

PitfallsWhere people go wrong

Opening 1433 for a named instance. The instance is on a dynamic port, the Browser is on 1434, and the rule opens neither.

Allowing inbound UDP 1434 from the internet. It answers anyone who asks which MSSQL instances exist and on which ports. If the Browser has to run, it belongs behind the same scoped rule as the instance.

Treating a moved port as a secured port. A scanner finds a SQL Server on 14330 as easily as on 1433. The effort belongs in scoping the rule and in authentication.

Assuming the port is fixed. A named instance on a dynamic port can come back on a different port after a restart, and the firewall rule that worked yesterday is now pointing at nothing.

Forgetting the admin connection exists. The DAC is local only by default, which is the right default. Turning on remote admin connections is a decision to write down, because it adds a second way in on a second port.

Leaving TrustServerCertificate on. It makes the connection error go away and the protection with it.

Migrating to Azure SQL with a 1433 rule. It works in Proxy mode and misbehaves in Redirect mode, and Redirect is the one Microsoft recommends.

THREE WAYS IN, AND ONLY ONE OF THEM IS JUST 1433DEFAULT INSTANCECLIENTTCP 1433DEFAULT INSTANCENAMED INSTANCE OR EXPRESSCLIENTUDP 1434SQL SERVER BROWSERNAMED INSTANCEdynamic port, or the one you fixAZURE SQL DATABASE, REDIRECT POLICYCLIENTTCP 1433GATEWAYDATABASE NODETCP 11000 to 11999
Only the first row is a connection to 1433 alone. A named instance is found through UDP 1434 and answers on its own port, and Azure SQL under Redirect starts on 1433 and continues on 11000 to 11999.

Comparison1433 and the ports around it

CriterionTCP 1433UDP 1434TCP 1434TCP 11000 to 11999
What listensDefault instanceSQL Server BrowserDedicated admin connectionAzure SQL nodes
Needed by clientsDefault instance onlyNamed instances without a fixed portAdministrators onlyAzure SQL with Redirect
On by defaultYes, if enabledDepends on the installLocal onlyAzure side
Fixed numberYesYesIf availableRange
Microsoft's security adviceScope the ruleLeave the service stoppedKeep it localUse service tags
Belongs on the internetNoNoNoOutbound only

The second column is the one to close first: it is the only one that exists to tell a stranger what else is running.

FAQFrequently asked questions

What is the 1433 port used for?

It is the TCP port the default instance of Microsoft SQL Server listens on for client connections and data access. Applications, reporting tools and SQL Server Management Studio connect to it when they reach a server by name without an instance name.

Is port 1433 TCP or UDP?

TCP. The UDP port associated with SQL Server is 1434, used by the SQL Server Browser service.

What is port 1434 used for?

Two things. UDP 1434 is the SQL Server Browser, which tells clients which port a named instance is on. TCP 1434 is where SQL Server listens for the dedicated administrator connection when that port is available.

Why can I not connect even though port 1433 is open?

Usually because the instance is a named instance or SQL Server Express, which listen on dynamic ports rather than 1433. Check the SQL Server error log for the port actually in use, and either open that port and UDP 1434 or fix the instance to a specific port.

How do I find which port SQL Server is using?

Microsoft points to the SQL Server error log, which records the port the Database Engine is listening on. SQL Server Configuration Manager shows the TCP/IP settings for each instance.

Is it safe to change port 1433 to something else?

It can help in some environments, and it is not protection. Microsoft states that because a port scanner can query for open ports, changing the port number is not considered a robust security measure.

Should port 1433 be open to the internet?

No. Windows Firewall closes it by default, and any inbound rule that allows it should be scoped to the specific servers or subnets whose applications need the database.

Does Azure SQL Database use port 1433?

At the gateway, yes. With the recommended Redirect connection policy, clients also need outbound access to ports 11000 to 11999 on the Azure SQL addresses in the region. With Proxy, all traffic stays on 1433 through the gateway.

Should the SQL Server Browser service run?

Only if clients cannot be configured with the port number. Microsoft's advice for the most secure environment is to leave it stopped and connect by port.

Is traffic on port 1433 encrypted?

Not by virtue of the port. Encryption is a connection setting, and SQL Server 2022 added strict encryption for TDS 8.0, under which a client cannot simply trust whatever certificate the server presents.

What is the dedicated administrator connection?

A separate connection for administrators when SQL Server is not responding normally. It listens on TCP 1434 if available, accepts local connections only by default, and is reached with the admin: prefix.

What should an MSP check on a client's SQL Server?

Which instances exist and on which ports, whether the Browser is running, whether any rule opens 1433 or 1434 wider than the application servers, whether remote admin connections were turned on, and whether connection strings set TrustServerCertificate to true.

What is the SQL Server default port, and is port 1433 secure?

The SQL Server default port is TCP 1433 for the default instance. Named instances use dynamic ports, which the SQL Server Browser service on UDP 1434 announces. Is port 1433 secure? Only inside a trusted network. It should never face the internet, because it is scanned constantly for weak sa passwords.

Read next · Ports What Is a Port Number? What a port number is, and why TCP and UDP can use the same one for different things. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.