Common TCP and UDP Ports

Search the ports you meet most often, with a note on whether each one belongs on the internet.

PortProtocolServiceExposureNotes
20TCPFTP dataRestrict accessData channel of active-mode FTP. Unencrypted, prefer SFTP.
21TCPFTP controlRestrict accessPlain-text logins. Use SFTP (port 22) or FTPS instead.
22TCPSSH, SFTPRestrict accessLimit to known IPs where you can. See the allow SSH tool.
23TCPTelnetDo not exposeSends everything in clear text. Replace with SSH.
25TCPSMTPFine to exposeServer-to-server mail. Many cloud providers block outbound port 25 by default.
53TCP/UDPDNSFine to exposeOpen only if you run a public DNS server. Disable open recursion.
67UDPDHCP serverRestrict accessLAN only. Port 68 is the client side.
69UDPTFTPDo not exposeNo authentication. Keep inside a trusted network.
80TCPHTTPFine to exposeUnencrypted web traffic. Keep it open to redirect to HTTPS and for certificate validation.
110TCPPOP3Restrict accessPlain-text mail retrieval. Use 995.
123UDPNTPRestrict accessNeeded by clients going out. Do not run a public NTP server unintentionally.
143TCPIMAPRestrict accessPlain-text mail access. Use 993.
161UDPSNMPRestrict accessMonitoring. Restrict to your monitoring host and avoid default community strings.
179TCPBGPRestrict accessRouting between peers. Allow only configured neighbors.
389TCP/UDPLDAPRestrict accessDirectory service. Use LDAPS (636) or StartTLS and keep it internal.
443TCP/UDPHTTPS (and HTTP/3)Fine to exposeEncrypted web traffic. HTTP/3 uses UDP on the same number.
445TCPSMBDo not exposeWindows file sharing. Never expose to the internet; a frequent ransomware entry point.
465TCPSMTPSFine to exposeMail submission over implicit TLS.
500UDPIPsec IKEFine to exposeUsed with 4500 (NAT traversal) for IPsec VPNs.
514UDPSyslogRestrict accessUnauthenticated log delivery. Accept from your own hosts only.
587TCPSMTP submissionFine to exposeMail submission with StartTLS and authentication.
636TCPLDAPSRestrict accessLDAP over TLS. Keep internal.
873TCPrsync daemonRestrict accessOnly if you run rsyncd. Restrict by source IP.
993TCPIMAPSFine to exposeIMAP over TLS.
995TCPPOP3SFine to exposePOP3 over TLS.
1194UDPOpenVPNFine to exposeDefault OpenVPN port. TCP is also possible.
1433TCPMicrosoft SQL ServerDo not exposeKeep behind a VPN or a source-IP allow list.
1521TCPOracle Database listenerDo not exposeRestrict to application servers.
2049TCP/UDPNFSDo not exposeInternal only. NFS has weak network-level authentication.
2375TCPDocker API (no TLS)Do not exposeAnyone who reaches it controls the host. Never expose.
2376TCPDocker API (TLS)Restrict accessOnly with client certificates and a source allow list.
3306TCPMySQL, MariaDBDo not exposeBind to localhost or allow only application servers. Details.
3389TCPRDPDo not exposeHeavily attacked. Put it behind a VPN. Details.
5060TCP/UDPSIPRestrict accessVoIP signalling, frequently scanned. Use 5061 for TLS.
5432TCPPostgreSQLDo not exposeDefault is localhost only. Details.
5900TCPVNCDo not exposeWeak protocol security. Tunnel over SSH or a VPN.
6379TCPRedisDo not exposeExposed Redis servers are a classic compromise. Details.
6443TCPKubernetes API serverRestrict accessRestrict to admin networks and nodes.
8080TCPHTTP alternateFine to exposeCommon for proxies and app servers behind a reverse proxy.
8443TCPHTTPS alternateFine to exposeCommon for admin panels and alternative TLS services.
9200TCPElasticsearch HTTPDo not exposeOlder setups had no authentication. Keep internal.
11211TCP/UDPMemcachedDo not exposeNo authentication by default, and abused for amplification attacks.
27017TCPMongoDBDo not exposeBind to localhost and enable authentication. Details.
51820UDPWireGuardFine to exposeConventional default; WireGuard has no fixed official port.

How to read the exposure column

Fine to expose means the service is meant to face the internet, when you actually run it. Restrict access means limit it to trusted networks or known IPs. Do not expose means do not publish it to the whole internet: keep it on localhost, behind a VPN, or limited to specific source addresses. This is general guidance, not a substitute for reviewing your own setup.

Turn a port into a firewall rule

Use the iptables generator for a single rule, or allow a port from specific IPs to publish a service to chosen addresses only. Ports numbered 0 to 1023 are the well-known range, 1024 to 49151 are registered, and the rest are dynamic.

FAQ

What are the most common ports?

80 (HTTP), 443 (HTTPS), 22 (SSH), 25 and 587 (mail), 53 (DNS), 3306 (MySQL), 5432 (PostgreSQL) and 3389 (RDP) are among the ones you meet most often.

What is the difference between TCP and UDP ports?

They are separate port spaces. TCP is connection-oriented and reliable, UDP is connectionless. The same number can be used by different services on each.

Which ports should never be open to the internet?

Database, file-sharing and remote-management ports such as 3306, 5432, 6379, 27017, 445, 3389 and 2375 should stay behind a VPN or an allow list.

© PacketUtils. Tools run in your browser. Review every command before using it in production.HomeAboutContactPrivacy Policy