Networking · Concept · 12 min read

What Is a Port Number? How One Address Serves Fifty Applications

Sixteen bits in a header, and an agreement about what they mean. Here is what a port actually is, why nothing is physically opened or closed, and why a single server holds fifty thousand connections on one of them.

Written by Marko Ristic, Editor Updated Sep 10, 2026
65,536Port numbers per protocol, because the field is 16 bits
1023The last port that needs privilege to bind on Unix
4Numbers that identify a TCP connection, not one
28kEphemeral ports available toward a single destination
Short answer

A port number is a 16 bit number, 0 to 65535, that tells a device which application a packet belongs to. The IP address finds the device on the network.

The port number finds the application on it, which is why one server with one address runs a website, a mail service and a database at once. TCP and UDP have separate sets, so TCP 53 and UDP 53 are different ports.

  • 65,536 per protocol, and TCP and UDP each get their own set
  • Nothing is physically opened: a port is a claim on a number
  • A connection is four numbers, which is why one port holds thousands
  • Below 1024 needs privilege to bind, and that rule is enforced
  • Ports 445 and 3389 should never face the internet
On this page

FundamentalsWhat a port actually is

A port is not a physical thing and not a piece of hardware on the device. It is a number in the header of every TCP and UDP packet, and an agreement about what that number means.

When an application wants to receive network data, it asks the operating system to listen on a port number. The operating system records that claim. From then on, any packet arriving at the device with that destination port number is handed to that application and to nothing else.

That is the entire mechanism. There is no port sitting inside the device waiting to be opened, and nothing is physically closed. A closed port is simply a number no application has claimed, and the operating system answers a packet for it by saying nobody is here, or by saying nothing at all if a firewall got there first.

Port numbers belong to the transport layer, the layer above IP. IP carries a packet to a device on the network and stops there, with no idea what any of the data is for.

TCP and UDP add the source and destination port numbers, and that is the whole of the addition: two 16 bit fields that turn one device address into thousands of separate communication endpoints. Nothing below the transport layer knows port numbers exist, which is why network switches forward frames without ever reading one, and routers route packets the same way.

The address analogy is worn out and it is accurate. The IP address is the building and the port number is the apartment. What it leaves out is that the apartment only exists while somebody is living in it, which is why the same port number is closed on one device and open on the next.

The rangesThe three ranges of port numbers

The port numbers are divided into three bands, and the division is convention backed by one rule the operating system actually enforces.

Well known ports, 0 to 1023. Assigned by IANA to specific network services. On Unix like systems, binding to one of these requires root or an explicit capability, which is a real security control: an ordinary user cannot start an application on port 80 and pretend to be the web server.

Registered ports, 1024 to 49151. Also assigned by IANA, on request, to particular applications. The assignment is a convention rather than a rule, and any application may use one. Port 4444 is the clearest example: it carries two separate registrations, the registry notes that one of them squatted on it, and neither is in use.

Dynamic or ephemeral ports, 49152 to 65535. Never assigned to any service. The operating system hands these out to client applications that need a source port for an outgoing connection.

In practice the actual range differs by system, and Linux typically uses 32768 upward, which is one of the reasons a firewall rule written against the official range sometimes drops traffic that should have passed.

The four tupleThe four numbers that identify a connection

This is the part that clears up the most confusion, and it is the reason a single device holds thousands of network connections at once.

A TCP connection is identified by four numbers together, called the four tuple: the source address, the source port, the destination address, and the destination port. Two connections are different if any one of those four numbers differs.

So when a browser opens six connections to the same web server, all six have the same destination address and the same destination port number, 443. What differs is the source port number, and the operating system picked a different ephemeral one for each. The server tells them apart on that basis and nothing else.

Two consequences worth carrying.

A server does not use one port per client. It listens on 443 and every connection arrives there. The four numbers separate them, so a busy web server has one listening port and fifty thousand network connections.

A client device can run out of source ports. Roughly 28,000 ephemeral ports, and each connection to the same destination needs a distinct one. A device making very high volumes of outbound connections to a single address, a load balancer or a proxy, hits that ceiling, and the symptom is connections failing while the network looks fine.

The common onesThe ports worth knowing

Not a list of all 65,536 ports. The ones that come up in real network work.

PortProtocolServiceNote
22TCPSSHAlso SFTP, which is not FTPS
25TCPSMTPServer to server mail traffic, usually blocked outbound
53UDP and TCPDNSTCP for large answers and zone transfers
67 and 68UDPDHCPServer and client
80TCPHTTPNow mostly a redirect to 443
123UDPNTPTime, and Kerberos fails without it
143 and 993TCPIMAP993 is the encrypted one
389 and 636TCPLDAP636 is LDAPS
443TCP and UDPHTTPSUDP 443 is HTTP/3 over QUIC
445TCPSMBFile sharing services, never expose it
587TCPSMTP submissionWhat a mail client actually uses
3389TCP and UDPRDPRemote desktop, never expose it either

Two rows in that table are worth reading twice. Port number 443 now carries UDP data as well as TCP, because HTTP/3 runs over the QUIC protocol, and a firewall that only permits TCP 443 quietly forces every browser back to the older protocol.

And 445 and 3389 are the two ports behind a large share of ransomware entry, which is why every hardening guide puts those services behind a VPN.

Plaintext and TLSThe secure and insecure pairs

A large part of the port list exists twice, because most network protocols were designed before encryption was assumed and then given a second port number for the secure version. Knowing the pairs is most of what a hardening review needs.

ServicePlaintextSecureHow the secure one works
Web80443A separate port, TLS from the first byte
Mail submission25587 or 465587 upgrades in place, 465 is TLS immediately
Mailbox access, IMAP143993A separate port
Mailbox access, POP3110995A separate port
Directory, LDAP389636A separate port
File transfer2122, or 990SFTP is SSH, FTPS is TLS over FTP
Remote shell23, telnet22, SSHTelnet has no encryption at all

Two patterns run through that table. Some protocols got a second port where the communication is encrypted from the first byte. Others kept one port and added a command that upgrades the connection to TLS partway through, which is what STARTTLS does on 587 and on 143.

The upgrade approach is tidier and it has one weakness: a device in the middle that strips the upgrade offer leaves the communication in plaintext, and neither end necessarily notices.

The row worth acting on is the last one. Telnet on port number 23 sends credentials in the clear across the network, and it is still enabled on a surprising number of switches, printers and other network devices. Finding it is a five minute scan and turning it off is usually one line of configuration.

Port forwardingPort forwarding, and what it is really doing

A home or office router holds one public address for a whole network of private ones. Nothing on the internet reaches an internal device directly, because its address is not routable.

Port forwarding is the rule that fixes this for one service. It says data arriving at the public address on a given port number should be rewritten and sent to a specific internal device and port. The router keeps the translation and sends the replies back the way they came.

Three things follow that people get wrong.

The external and internal ports do not have to match. Forwarding external 8443 to internal 443 is common and slightly reduces automated scanning.

A forwarded port is exposed to the entire internet. Every device on the internet reaches it within minutes of it opening, because the whole address space is scanned continuously. Forwarding RDP or SMB is how a large share of breaches begin.

One external port forwards to one internal device. Two servers both wanting external 443 need either different external port numbers or something in front of them that reads the request and decides, which is a reverse proxy rather than a router.

PitfallsWhere people go wrong

Assuming a port is either open or closed. There are three answers. Open means an application is listening. Closed means no service is listening and the device said so. Filtered means a firewall dropped the packet and nothing answered at all, which is why scanning a filtered port takes so long.

Believing TCP 53 and UDP 53 are the same port. They are separate port numbers in separate protocol namespaces. DNS uses both, UDP for ordinary queries and TCP for answers too large for a datagram and for zone transfers. A firewall permitting only UDP 53 breaks in ways that look intermittent.

Changing SSH to a high port and calling it security. It reduces log noise from automated network scanning and it stops nothing that is looking for you specifically. Do it if the noise bothers you, and do not count it as a control.

Forgetting that the source port is random. A firewall rule that pins a source port works in testing and fails in production, because the next connection picks a different one.

Exposing a database port number. MySQL on 3306 and PostgreSQL on 5432 reachable from the internet is a finding in every network audit, and it is more common than it should be on cloud instances where the default security group was left wide.

Running out of ephemeral ports and blaming the network. A device holding tens of thousands of connections in TIME_WAIT to one destination fails to open new ones while every other network test passes.

How to checkChecking what is actually listening

The commands that list every listening port number, on the three platforms.

# Linux, the modern one
ss -tulpn

# Linux, the old one that is still everywhere
netstat -tulpn

# Windows, with the owning process
netstat -ano

# macOS
lsof -i -P -n | grep LISTEN

Read the local address column first. A service bound to 127.0.0.1 is reachable only from the device itself, which is usually what you want for a database. A service bound to 0.0.0.0 is listening on every network interface the device has, including one facing the internet, and that distinction is the difference between a safe default and an incident.

THREE CONNECTIONS, ONE LAPTOP, ONE WEB SERVERSOURCE ADDRESSSOURCE PORTDESTINATIONDEST PORT192.168.1.2051314203.0.113.10443192.168.1.2051315203.0.113.10443192.168.1.2051316203.0.113.10443123Three of the four columns are identical. The one that differs is the source port, which theoperating system picked from the ephemeral range, and it is the only thing keeping the threeconnections apart at either end.That is why one server listens on a single port and holds fifty thousand connections at once.
Three connections to the same server. Only one column differs, and it is the reason a single listening port serves everybody.

ComparisonThe three port ranges, and what is actually enforced about each

CriterionWell knownRegisteredEphemeral
Range0 to 10231024 to 4915149152 to 65535
Assigned by IANAYesYes, on requestNo
Needs privilege to bindYesNoNo
Used by serversYesYesRarely
Used as a client source portNoSometimesYes
Safe to pick one arbitrarilyNoSometimesYes, the system does
Where a network service listensYesSometimesNo

The privilege row is the one with teeth. Everything else is convention, and that row is enforced by the operating system.

FAQFrequently asked questions

What is a port number in simple terms?

A number that says which application on a device a packet is for. The IP address finds the device on the network, the port number finds the application on it.

How many port numbers are there?

65,536 per protocol, numbered 0 to 65535, because the field is 16 bits. TCP and UDP have separate sets of port numbers.

What is the difference between a TCP port and a UDP port?

They are different namespaces in different transport protocols. Port number 53 in TCP and 53 in UDP are unrelated, and an application listening on one hears no traffic from the other.

What are well known ports?

Port numbers 0 to 1023, assigned by IANA to specific network services. On Unix like systems an application needs root or a capability to listen on one.

What is an ephemeral port?

A temporary source port number the operating system assigns to an outgoing connection. It exists for the life of that connection and is then returned to the pool.

Can two applications use the same port number?

Not on the same address and transport protocol. One can bind to 127.0.0.1:8080 while another binds to 192.168.1.10:8080, and options such as SO_REUSEPORT let processes share a port deliberately, which is how some web servers scale across cores.

Is changing the SSH port a security measure?

It reduces automated noise in the logs. It does not stop a targeted attacker, who will scan every port. Treat it as tidiness rather than defense.

What does a filtered port mean in a network scan?

That nothing answered at all, because a firewall dropped the packet. A closed port replies to say no service is listening. Silence means something in between decided not to.

Why is port number 445 dangerous?

It carries SMB file sharing services, it is scanned constantly, and the protocol has a history of remotely exploitable flaws. It should never be reachable from the internet.

What is port forwarding?

A router rule that sends traffic arriving at the public address on one port number to a specific internal device and port, so a service behind NAT can be reached from outside the network.

What is the difference between 0.0.0.0 and 127.0.0.1 in a listener?

127.0.0.1 accepts connections only from the device itself. 0.0.0.0 accepts them on every network interface, including any facing the internet.

Can I run out of port numbers?

Yes, on the client side. Around 28,000 ephemeral port numbers are available for connections to a single destination, and a device making very high volumes of outbound connections to one address will exhaust them.

Read next · Network security What Is a Firewall? A firewall rule is mostly a statement about which ports may be reached from where. Open this next14 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.