In computer networking, an IP address identifies the destination hardware device, but ports identify the specific software application or service running on that device. Without ports, a computer would have no way to distinguish incoming web traffic from an incoming email or a gaming packet.

1. The Apartment Complex Analogy

Imagine a 500-unit residential apartment building:

There are exactly 65,535 possible ports for TCP, and another 65,535 ports for UDP, governed by the Internet Assigned Numbers Authority (IANA).

๐Ÿ›ก๏ธ

Is Your Public IP Exposing Vulnerable Ports?

Scan your WAN IP right now to verify that your firewall is actively blocking critical services like SSH (22), SMB (445), and RDP (3389).

Run Free Port Scanner Audit →

2. Port Ranges: Well-Known vs. Registered vs. Ephemeral

3. The Essential Network Ports Cheat Sheet

Port Protocol Service Description & Security Advice
20 / 21 TCP FTP (File Transfer) Transmits credentials in plaintext. Replace with SFTP (Port 22).
22 TCP SSH / SFTP Secure encrypted terminal and file transfers. Never use passwords; require SSH keys.
23 TCP Telnet Legacy unencrypted terminal. Extremely dangerous if exposed to the WAN.
25 TCP SMTP Mail server-to-server relaying. Blocked by most consumer ISPs to prevent spam.
53 TCP/UDP DNS (Domain Name System) Translates domain names to IP addresses. UDP for queries; TCP for zone transfers.
80 TCP HTTP Unencrypted web traffic. Always redirect traffic to HTTPS (Port 443).
110 TCP POP3 Legacy email retrieval. Replaced by POP3S on Port 995.
123 UDP NTP (Network Time) Synchronizes clocks across network devices. Susceptible to NTP amplification attacks.
143 TCP IMAP Standard email retrieval. Replaced by IMAPS on Port 993.
443 TCP HTTPS / TLS Encrypted secure web browsing. Standard for modern web security.
445 TCP SMB (Server Message Block) Windows file sharing. The vector for WannaCry and EternalBlue. NEVER expose to the internet!
3389 TCP/UDP RDP (Remote Desktop) Microsoft Remote Desktop. Prime target for brute-force ransomware attacks. Put behind a VPN.
8080 / 8443 TCP HTTP-Alternate Commonly used for development web servers, proxies, and admin consoles.

4. How to Check Open Ports on Your Machine

To inspect which ports are currently listening for incoming connections on your operating system:

SECURITY WARNING

The Golden Rule of Firewall Hardening

Adopt a Default-Deny posture. Block all incoming ports by default on your WAN boundary, and only open specific ports when wrapped in cryptographic authentication (WireGuard, IPsec, or Cloudflare Tunnels).