Common TCP and UDP Ports
Search the ports you meet most often, with a note on whether each one belongs on the internet.
| Port | Protocol | Service | Exposure | Notes |
|---|---|---|---|---|
20 | TCP | FTP data | Restrict access | Data channel of active-mode FTP. Unencrypted, prefer SFTP. |
21 | TCP | FTP control | Restrict access | Plain-text logins. Use SFTP (port 22) or FTPS instead. |
22 | TCP | SSH, SFTP | Restrict access | Limit to known IPs where you can. See the allow SSH tool. |
23 | TCP | Telnet | Do not expose | Sends everything in clear text. Replace with SSH. |
25 | TCP | SMTP | Fine to expose | Server-to-server mail. Many cloud providers block outbound port 25 by default. |
53 | TCP/UDP | DNS | Fine to expose | Open only if you run a public DNS server. Disable open recursion. |
67 | UDP | DHCP server | Restrict access | LAN only. Port 68 is the client side. |
69 | UDP | TFTP | Do not expose | No authentication. Keep inside a trusted network. |
80 | TCP | HTTP | Fine to expose | Unencrypted web traffic. Keep it open to redirect to HTTPS and for certificate validation. |
110 | TCP | POP3 | Restrict access | Plain-text mail retrieval. Use 995. |
123 | UDP | NTP | Restrict access | Needed by clients going out. Do not run a public NTP server unintentionally. |
143 | TCP | IMAP | Restrict access | Plain-text mail access. Use 993. |
161 | UDP | SNMP | Restrict access | Monitoring. Restrict to your monitoring host and avoid default community strings. |
179 | TCP | BGP | Restrict access | Routing between peers. Allow only configured neighbors. |
389 | TCP/UDP | LDAP | Restrict access | Directory service. Use LDAPS (636) or StartTLS and keep it internal. |
443 | TCP/UDP | HTTPS (and HTTP/3) | Fine to expose | Encrypted web traffic. HTTP/3 uses UDP on the same number. |
445 | TCP | SMB | Do not expose | Windows file sharing. Never expose to the internet; a frequent ransomware entry point. |
465 | TCP | SMTPS | Fine to expose | Mail submission over implicit TLS. |
500 | UDP | IPsec IKE | Fine to expose | Used with 4500 (NAT traversal) for IPsec VPNs. |
514 | UDP | Syslog | Restrict access | Unauthenticated log delivery. Accept from your own hosts only. |
587 | TCP | SMTP submission | Fine to expose | Mail submission with StartTLS and authentication. |
636 | TCP | LDAPS | Restrict access | LDAP over TLS. Keep internal. |
873 | TCP | rsync daemon | Restrict access | Only if you run rsyncd. Restrict by source IP. |
993 | TCP | IMAPS | Fine to expose | IMAP over TLS. |
995 | TCP | POP3S | Fine to expose | POP3 over TLS. |
1194 | UDP | OpenVPN | Fine to expose | Default OpenVPN port. TCP is also possible. |
1433 | TCP | Microsoft SQL Server | Do not expose | Keep behind a VPN or a source-IP allow list. |
1521 | TCP | Oracle Database listener | Do not expose | Restrict to application servers. |
2049 | TCP/UDP | NFS | Do not expose | Internal only. NFS has weak network-level authentication. |
2375 | TCP | Docker API (no TLS) | Do not expose | Anyone who reaches it controls the host. Never expose. |
2376 | TCP | Docker API (TLS) | Restrict access | Only with client certificates and a source allow list. |
3306 | TCP | MySQL, MariaDB | Do not expose | Bind to localhost or allow only application servers. Details. |
3389 | TCP | RDP | Do not expose | Heavily attacked. Put it behind a VPN. Details. |
5060 | TCP/UDP | SIP | Restrict access | VoIP signalling, frequently scanned. Use 5061 for TLS. |
5432 | TCP | PostgreSQL | Do not expose | Default is localhost only. Details. |
5900 | TCP | VNC | Do not expose | Weak protocol security. Tunnel over SSH or a VPN. |
6379 | TCP | Redis | Do not expose | Exposed Redis servers are a classic compromise. Details. |
6443 | TCP | Kubernetes API server | Restrict access | Restrict to admin networks and nodes. |
8080 | TCP | HTTP alternate | Fine to expose | Common for proxies and app servers behind a reverse proxy. |
8443 | TCP | HTTPS alternate | Fine to expose | Common for admin panels and alternative TLS services. |
9200 | TCP | Elasticsearch HTTP | Do not expose | Older setups had no authentication. Keep internal. |
11211 | TCP/UDP | Memcached | Do not expose | No authentication by default, and abused for amplification attacks. |
27017 | TCP | MongoDB | Do not expose | Bind to localhost and enable authentication. Details. |
51820 | UDP | WireGuard | Fine to expose | Conventional default; WireGuard has no fixed official port. |
No matching port.
How to read the exposure column
Fine to expose means the service is meant to face the internet, when you actually run it. Restrict access means limit it to trusted networks or known IPs. Do not expose means do not publish it to the whole internet: keep it on localhost, behind a VPN, or limited to specific source addresses. This is general guidance, not a substitute for reviewing your own setup.
Turn a port into a firewall rule
Use the iptables generator for a single rule, or allow a port from specific IPs to publish a service to chosen addresses only. Ports numbered 0 to 1023 are the well-known range, 1024 to 49151 are registered, and the rest are dynamic.
FAQ
What are the most common ports?
80 (HTTP), 443 (HTTPS), 22 (SSH), 25 and 587 (mail), 53 (DNS), 3306 (MySQL), 5432 (PostgreSQL) and 3389 (RDP) are among the ones you meet most often.
What is the difference between TCP and UDP ports?
They are separate port spaces. TCP is connection-oriented and reliable, UDP is connectionless. The same number can be used by different services on each.
Which ports should never be open to the internet?
Database, file-sharing and remote-management ports such as 3306, 5432, 6379, 27017, 445, 3389 and 2375 should stay behind a VPN or an allow list.