In computer networking, an IP address identifies the destination hardware device, but ports identify the specific software application or service running on that device. Without ports, a computer would have no way to distinguish incoming web traffic from an incoming email or a gaming packet.
1. The Apartment Complex Analogy
Imagine a 500-unit residential apartment building:
- The street address of the building is like the IP Address. It gets postal trucks to the right physical structure.
- The apartment unit number (e.g. Apt 443 or Apt 22) is the Port Number. It delivers the package to the exact resident waiting inside.
There are exactly 65,535 possible ports for TCP, and another 65,535 ports for UDP, governed by the Internet Assigned Numbers Authority (IANA).
Is Your Public IP Exposing Vulnerable Ports?
Scan your WAN IP right now to verify that your firewall is actively blocking critical services like SSH (22), SMB (445), and RDP (3389).
Run Free Port Scanner Audit →2. Port Ranges: Well-Known vs. Registered vs. Ephemeral
- 0 โ 1,023 (Well-Known / System Ports): Reserved for foundational operating system services (HTTP, HTTPS, SSH, DNS, SMTP). Requires root or administrator privileges to bind.
- 1,024 โ 49,151 (Registered Ports): Assigned by IANA for specific user applications (MySQL 3306, PostgreSQL 5432, RDP 3389, OpenVPN 1194).
- 49,152 โ 65,535 (Dynamic / Private / Ephemeral Ports): Automatically assigned by client operating systems for temporary outbound outbound connections.
3. The Essential Network Ports Cheat Sheet
| Port | Protocol | Service | Description & Security Advice |
|---|---|---|---|
| 20 / 21 | TCP | FTP (File Transfer) | Transmits credentials in plaintext. Replace with SFTP (Port 22). |
| 22 | TCP | SSH / SFTP | Secure encrypted terminal and file transfers. Never use passwords; require SSH keys. |
| 23 | TCP | Telnet | Legacy unencrypted terminal. Extremely dangerous if exposed to the WAN. |
| 25 | TCP | SMTP | Mail server-to-server relaying. Blocked by most consumer ISPs to prevent spam. |
| 53 | TCP/UDP | DNS (Domain Name System) | Translates domain names to IP addresses. UDP for queries; TCP for zone transfers. |
| 80 | TCP | HTTP | Unencrypted web traffic. Always redirect traffic to HTTPS (Port 443). |
| 110 | TCP | POP3 | Legacy email retrieval. Replaced by POP3S on Port 995. |
| 123 | UDP | NTP (Network Time) | Synchronizes clocks across network devices. Susceptible to NTP amplification attacks. |
| 143 | TCP | IMAP | Standard email retrieval. Replaced by IMAPS on Port 993. |
| 443 | TCP | HTTPS / TLS | Encrypted secure web browsing. Standard for modern web security. |
| 445 | TCP | SMB (Server Message Block) | Windows file sharing. The vector for WannaCry and EternalBlue. NEVER expose to the internet! |
| 3389 | TCP/UDP | RDP (Remote Desktop) | Microsoft Remote Desktop. Prime target for brute-force ransomware attacks. Put behind a VPN. |
| 8080 / 8443 | TCP | HTTP-Alternate | Commonly used for development web servers, proxies, and admin consoles. |
4. How to Check Open Ports on Your Machine
To inspect which ports are currently listening for incoming connections on your operating system:
- Windows (PowerShell / Command Prompt):
netstat -ano | findstr LISTENING - Linux & macOS (Terminal):
sudo ss -tulpnorsudo lsof -i -P -n | grep LISTEN
The Golden Rule of Firewall Hardening
Adopt a Default-Deny posture. Block all incoming ports by default on your WAN boundary, and only open specific ports when wrapped in cryptographic authentication (WireGuard, IPsec, or Cloudflare Tunnels).