A port number is a 16 bit number, 0 to 65535, that tells a device which application a packet belongs to. The IP address finds the device on the network.
The port number finds the application on it, which is why one server with one address runs a website, a mail service and a database at once. TCP and UDP have separate sets, so TCP 53 and UDP 53 are different ports.
- 65,536 per protocol, and TCP and UDP each get their own set
- Nothing is physically opened: a port is a claim on a number
- A connection is four numbers, which is why one port holds thousands
- Below 1024 needs privilege to bind, and that rule is enforced
- Ports 445 and 3389 should never face the internet
On this page
FundamentalsWhat a port actually is
A port is not a physical thing and not a piece of hardware on the device. It is a number in the header of every TCP and UDP packet, and an agreement about what that number means.
When an application wants to receive network data, it asks the operating system to listen on a port number. The operating system records that claim. From then on, any packet arriving at the device with that destination port number is handed to that application and to nothing else.
That is the entire mechanism. There is no port sitting inside the device waiting to be opened, and nothing is physically closed. A closed port is simply a number no application has claimed, and the operating system answers a packet for it by saying nobody is here, or by saying nothing at all if a firewall got there first.
Port numbers belong to the transport layer, the layer above IP. IP carries a packet to a device on the network and stops there, with no idea what any of the data is for.
TCP and UDP add the source and destination port numbers, and that is the whole of the addition: two 16 bit fields that turn one device address into thousands of separate communication endpoints. Nothing below the transport layer knows port numbers exist, which is why network switches forward frames without ever reading one, and routers route packets the same way.
The address analogy is worn out and it is accurate. The IP address is the building and the port number is the apartment. What it leaves out is that the apartment only exists while somebody is living in it, which is why the same port number is closed on one device and open on the next.
The rangesThe three ranges of port numbers
The port numbers are divided into three bands, and the division is convention backed by one rule the operating system actually enforces.
Well known ports, 0 to 1023. Assigned by IANA to specific network services. On Unix like systems, binding to one of these requires root or an explicit capability, which is a real security control: an ordinary user cannot start an application on port 80 and pretend to be the web server.
Registered ports, 1024 to 49151. Also assigned by IANA, on request, to particular applications. The assignment is a convention rather than a rule, and any application may use one. Port 4444 is the clearest example: it carries two separate registrations, the registry notes that one of them squatted on it, and neither is in use.
Dynamic or ephemeral ports, 49152 to 65535. Never assigned to any service. The operating system hands these out to client applications that need a source port for an outgoing connection.
In practice the actual range differs by system, and Linux typically uses 32768 upward, which is one of the reasons a firewall rule written against the official range sometimes drops traffic that should have passed.
The four tupleThe four numbers that identify a connection
This is the part that clears up the most confusion, and it is the reason a single device holds thousands of network connections at once.
A TCP connection is identified by four numbers together, called the four tuple: the source address, the source port, the destination address, and the destination port. Two connections are different if any one of those four numbers differs.
So when a browser opens six connections to the same web server, all six have the same destination address and the same destination port number, 443. What differs is the source port number, and the operating system picked a different ephemeral one for each. The server tells them apart on that basis and nothing else.
Two consequences worth carrying.
A server does not use one port per client. It listens on 443 and every connection arrives there. The four numbers separate them, so a busy web server has one listening port and fifty thousand network connections.
A client device can run out of source ports. Roughly 28,000 ephemeral ports, and each connection to the same destination needs a distinct one. A device making very high volumes of outbound connections to a single address, a load balancer or a proxy, hits that ceiling, and the symptom is connections failing while the network looks fine.
The common onesThe ports worth knowing
Not a list of all 65,536 ports. The ones that come up in real network work.
| Port | Protocol | Service | Note |
|---|---|---|---|
| 22 | TCP | SSH | Also SFTP, which is not FTPS |
| 25 | TCP | SMTP | Server to server mail traffic, usually blocked outbound |
| 53 | UDP and TCP | DNS | TCP for large answers and zone transfers |
| 67 and 68 | UDP | DHCP | Server and client |
| 80 | TCP | HTTP | Now mostly a redirect to 443 |
| 123 | UDP | NTP | Time, and Kerberos fails without it |
| 143 and 993 | TCP | IMAP | 993 is the encrypted one |
| 389 and 636 | TCP | LDAP | 636 is LDAPS |
| 443 | TCP and UDP | HTTPS | UDP 443 is HTTP/3 over QUIC |
| 445 | TCP | SMB | File sharing services, never expose it |
| 587 | TCP | SMTP submission | What a mail client actually uses |
| 3389 | TCP and UDP | RDP | Remote desktop, never expose it either |
Two rows in that table are worth reading twice. Port number 443 now carries UDP data as well as TCP, because HTTP/3 runs over the QUIC protocol, and a firewall that only permits TCP 443 quietly forces every browser back to the older protocol.
And 445 and 3389 are the two ports behind a large share of ransomware entry, which is why every hardening guide puts those services behind a VPN.
Plaintext and TLSThe secure and insecure pairs
A large part of the port list exists twice, because most network protocols were designed before encryption was assumed and then given a second port number for the secure version. Knowing the pairs is most of what a hardening review needs.
| Service | Plaintext | Secure | How the secure one works |
|---|---|---|---|
| Web | 80 | 443 | A separate port, TLS from the first byte |
| Mail submission | 25 | 587 or 465 | 587 upgrades in place, 465 is TLS immediately |
| Mailbox access, IMAP | 143 | 993 | A separate port |
| Mailbox access, POP3 | 110 | 995 | A separate port |
| Directory, LDAP | 389 | 636 | A separate port |
| File transfer | 21 | 22, or 990 | SFTP is SSH, FTPS is TLS over FTP |
| Remote shell | 23, telnet | 22, SSH | Telnet has no encryption at all |
Two patterns run through that table. Some protocols got a second port where the communication is encrypted from the first byte. Others kept one port and added a command that upgrades the connection to TLS partway through, which is what STARTTLS does on 587 and on 143.
The upgrade approach is tidier and it has one weakness: a device in the middle that strips the upgrade offer leaves the communication in plaintext, and neither end necessarily notices.
The row worth acting on is the last one. Telnet on port number 23 sends credentials in the clear across the network, and it is still enabled on a surprising number of switches, printers and other network devices. Finding it is a five minute scan and turning it off is usually one line of configuration.
Port forwardingPort forwarding, and what it is really doing
A home or office router holds one public address for a whole network of private ones. Nothing on the internet reaches an internal device directly, because its address is not routable.
Port forwarding is the rule that fixes this for one service. It says data arriving at the public address on a given port number should be rewritten and sent to a specific internal device and port. The router keeps the translation and sends the replies back the way they came.
Three things follow that people get wrong.
The external and internal ports do not have to match. Forwarding external 8443 to internal 443 is common and slightly reduces automated scanning.
A forwarded port is exposed to the entire internet. Every device on the internet reaches it within minutes of it opening, because the whole address space is scanned continuously. Forwarding RDP or SMB is how a large share of breaches begin.
One external port forwards to one internal device. Two servers both wanting external 443 need either different external port numbers or something in front of them that reads the request and decides, which is a reverse proxy rather than a router.
PitfallsWhere people go wrong
Assuming a port is either open or closed. There are three answers. Open means an application is listening. Closed means no service is listening and the device said so. Filtered means a firewall dropped the packet and nothing answered at all, which is why scanning a filtered port takes so long.
Believing TCP 53 and UDP 53 are the same port. They are separate port numbers in separate protocol namespaces. DNS uses both, UDP for ordinary queries and TCP for answers too large for a datagram and for zone transfers. A firewall permitting only UDP 53 breaks in ways that look intermittent.
Changing SSH to a high port and calling it security. It reduces log noise from automated network scanning and it stops nothing that is looking for you specifically. Do it if the noise bothers you, and do not count it as a control.
Forgetting that the source port is random. A firewall rule that pins a source port works in testing and fails in production, because the next connection picks a different one.
Exposing a database port number. MySQL on 3306 and PostgreSQL on 5432 reachable from the internet is a finding in every network audit, and it is more common than it should be on cloud instances where the default security group was left wide.
Running out of ephemeral ports and blaming the network. A device holding tens of thousands of connections in TIME_WAIT to one destination fails to open new ones while every other network test passes.
How to checkChecking what is actually listening
The commands that list every listening port number, on the three platforms.
# Linux, the modern one
ss -tulpn
# Linux, the old one that is still everywhere
netstat -tulpn
# Windows, with the owning process
netstat -ano
# macOS
lsof -i -P -n | grep LISTEN
Read the local address column first. A service bound to 127.0.0.1 is reachable only from the device itself, which is usually what you want for a database. A service bound to 0.0.0.0 is listening on every network interface the device has, including one facing the internet, and that distinction is the difference between a safe default and an incident.
ComparisonThe three port ranges, and what is actually enforced about each
| Criterion | Well known | Registered | Ephemeral |
|---|---|---|---|
| Range | 0 to 1023 | 1024 to 49151 | 49152 to 65535 |
| Assigned by IANA | Yes | Yes, on request | No |
| Needs privilege to bind | Yes | No | No |
| Used by servers | Yes | Yes | Rarely |
| Used as a client source port | No | Sometimes | Yes |
| Safe to pick one arbitrarily | No | Sometimes | Yes, the system does |
| Where a network service listens | Yes | Sometimes | No |
The privilege row is the one with teeth. Everything else is convention, and that row is enforced by the operating system.
FAQFrequently asked questions
What is a port number in simple terms?
A number that says which application on a device a packet is for. The IP address finds the device on the network, the port number finds the application on it.
How many port numbers are there?
65,536 per protocol, numbered 0 to 65535, because the field is 16 bits. TCP and UDP have separate sets of port numbers.
What is the difference between a TCP port and a UDP port?
They are different namespaces in different transport protocols. Port number 53 in TCP and 53 in UDP are unrelated, and an application listening on one hears no traffic from the other.
What are well known ports?
Port numbers 0 to 1023, assigned by IANA to specific network services. On Unix like systems an application needs root or a capability to listen on one.
What is an ephemeral port?
A temporary source port number the operating system assigns to an outgoing connection. It exists for the life of that connection and is then returned to the pool.
Can two applications use the same port number?
Not on the same address and transport protocol. One can bind to 127.0.0.1:8080 while another binds to 192.168.1.10:8080, and options such as SO_REUSEPORT let processes share a port deliberately, which is how some web servers scale across cores.
Is changing the SSH port a security measure?
It reduces automated noise in the logs. It does not stop a targeted attacker, who will scan every port. Treat it as tidiness rather than defense.
What does a filtered port mean in a network scan?
That nothing answered at all, because a firewall dropped the packet. A closed port replies to say no service is listening. Silence means something in between decided not to.
Why is port number 445 dangerous?
It carries SMB file sharing services, it is scanned constantly, and the protocol has a history of remotely exploitable flaws. It should never be reachable from the internet.
What is port forwarding?
A router rule that sends traffic arriving at the public address on one port number to a specific internal device and port, so a service behind NAT can be reached from outside the network.
What is the difference between 0.0.0.0 and 127.0.0.1 in a listener?
127.0.0.1 accepts connections only from the device itself. 0.0.0.0 accepts them on every network interface, including any facing the internet.
Can I run out of port numbers?
Yes, on the client side. Around 28,000 ephemeral port numbers are available for connections to a single destination, and a device making very high volumes of outbound connections to one address will exhaust them.
Keep readingRelated concepts
Read next · Network security What Is a Firewall? A firewall rule is mostly a statement about which ports may be reached from where. Open this next14 min- Addressing · 15 min What Is a Subnet? The address half of the pair. A subnet finds the device, a port finds the application on it.
- Protocols · 10 min TCP vs UDP Port numbers live in the TCP and UDP headers, and the two protocols keep separate sets of them.
- Protocols · 9 min Telnet, Why SSH Replaced It, and the One Job It Kept What a port test does and does not tell you.
- Cabling and connectivity · 10 min Cat6 vs Cat6a The physical layer underneath every port and connection on the network.
- Ports · 10 min Port 88, and Why a Domain Stops Working Without It The general idea behind every page in this series.
- Diagnostics · 11 min Ping and Traceroute What to test once ping has proved the host is reachable.
- Directory and identity · 13 min LDAP Explained The two ports this protocol lives on, and why one of them is a finding.
- Network security · 14 min What Is a WAF? The addressing a firewall filters on, and why it is not enough for web traffic.
- DNS · 14 min DNS Not Resolving The ports DNS runs on, and why permitting only the obvious one is a trap.
- Diagnostics · 12 min Reading a Wireshark Capture Without Drowning in Packets The numbers in the source and destination columns, and what they identify.
- Ports · 10 min Port 80 and 443, and Why You Still Cannot Close 80 What a port number is, and what the well known range means.
- Ports · 10 min Port 135, the Endpoint Mapper, and the Ports It Points At The general idea behind the port series.
- Ports · 10 min Port 53, and Why DNS Needs TCP as Well as UDP The one well known port that needs both transports, and what happens to a firewall rule that permits only UDP.
- Ports · 10 min Port 22, and Why Changing It Is Not the Fix People Think What the well known port range means, and why it matters here.
- Ports · 9 min SNMP Ports 161 and 162, and the Firewall Rule That Is Half Right A pair of ports that face in opposite directions.
- Ports · 8 min Port 4444, and Why an Abandoned Port Makes a Clean Signal A registered port that nothing ever claimed in practice.
- Ports · 9 min Port 110, and Why the Mail Keeps Coming Back One well known port in detail.
- Ports · 9 min The RDP Port, and Why It Should Not Be the One Facing the Internet One well known port in detail, and the second port that takes it off the internet.
- Ports · 10 min Port 1433, and Why SQL Server Is Rarely Only on 1433 A worked case where TCP 1434 and UDP 1434 belong to two different services.
- Addressing · 11 min IP Masquerading, and the One Case Where SNAT Is Better Why rewriting the port is the trick that works.