Top 20 Common Network Ports and Their Functions: A Beginner's Guide
Learn the top 20 most commonly used network ports, their protocols (TCP/UDP), and functions like HTTP, SSH, FTP, DNS, and more. Ideal for networking, cybersecurity, and IT beginners.
Quick answer: A network port is a 16-bit number (0 to 65535) that tells a device which service should receive incoming traffic. The most common ports are 22 (SSH), 25 (SMTP), 53 (DNS), 80 (HTTP), 443 (HTTPS), 3306 (MySQL) and 3389 (RDP). Together with the IP address and protocol (TCP or UDP), the port identifies one conversation.
Key takeaways
- An IP address finds the machine; the port finds the program on that machine. Both are needed for a connection.
- Ports 0 to 1023 are well-known, 1024 to 49151 are registered, and 49152 to 65535 are dynamic (used by clients for temporary connections).
- Some services use TCP, some UDP, some both. DNS uses UDP for most queries and TCP for large replies and zone transfers.
- Cleartext services (Telnet 23, FTP 21, POP3 110) should be replaced by encrypted ones (SSH, SFTP, POP3S or IMAPS).
- Every open port is attack surface. Know what is listening on your machines, and close what you do not need.
What is a network port?
A port is a number that a computer uses to sort incoming network traffic between its programs. Your laptop may run a browser, a mail client and an SSH session at the same time. All three share one IP address, so the operating system uses port numbers to hand each packet to the right program.
Think of an office building. The IP address is the building's street address. The port is the room number. A visitor needs both to reach the right person.
A single connection is identified by five values: source IP, source port, destination IP, destination port and protocol. When your browser opens a website, it connects from a random high port on your side (say 51514) to port 443 on the server. That is why thousands of people can all talk to the same server's port 443 at once without their traffic mixing.
The three port ranges
Port numbers are split into three ranges, as set out in RFC 6335 and maintained in the IANA service name and port number registry.
| Range | Name | What it is for |
|---|---|---|
| 0 to 1023 | System (well-known) ports | Standard services such as SSH, HTTP and DNS. On Linux, only a privileged process can listen on these. |
| 1024 to 49151 | Registered (user) ports | Applications registered with IANA, such as MySQL (3306) and RDP (3389). |
| 49152 to 65535 | Dynamic (ephemeral) ports | Temporary source ports chosen by the client for each outgoing connection. |
Linux and Windows do not both use exactly the 49152 to 65535 range for ephemeral ports. Linux commonly uses 32768 to 60999. You can check with cat /proc/sys/net/ipv4/ip_local_port_range. This is a detail, but it matters when you read firewall logs.
20 common network ports and what they do
This table lists the ports you will meet most often in networking, system administration and security work. Learn it the way you learn multiplication tables: by repetition, then by using it.
| Port | Protocol | Service | What it does |
|---|---|---|---|
| 20 | TCP | FTP data | Carries file data in active-mode FTP |
| 21 | TCP | FTP control | FTP login and commands; sends passwords in cleartext |
| 22 | TCP | SSH | Encrypted remote login; also used by SFTP and SCP |
| 23 | TCP | Telnet | Remote login with no encryption; avoid it |
| 25 | TCP | SMTP | Mail transfer between mail servers |
| 53 | UDP and TCP | DNS | Turns names into IP addresses; TCP for large replies and zone transfers |
| 67 | UDP | DHCP server | The DHCP server listens here |
| 68 | UDP | DHCP client | The DHCP client listens here for the server's reply |
| 69 | UDP | TFTP | Simple file transfer with no login; used for network device boot and config |
| 80 | TCP | HTTP | Unencrypted web traffic |
| 110 | TCP | POP3 | Downloads email; cleartext unless wrapped in TLS (POP3S uses 995) |
| 123 | UDP | NTP | Keeps clocks synchronised |
| 137 to 139 | UDP and TCP | NetBIOS | 137 UDP name service, 138 UDP datagram service, 139 TCP session service (legacy Windows networking) |
| 143 | TCP | IMAP | Reads email on the server; IMAPS uses 993 |
| 161 | UDP | SNMP | Network monitoring queries; traps go to 162 |
| 443 | TCP | HTTPS | Web traffic encrypted with TLS |
| 445 | TCP | SMB | Windows file and printer sharing |
| 587 | TCP | SMTP submission | Mail clients send outgoing mail to their server, normally with authentication and STARTTLS |
| 3306 | TCP | MySQL | MySQL and MariaDB database connections |
| 3389 | TCP | RDP | Windows Remote Desktop |
Two points to get right in port tables. NetBIOS name service is port 137, datagram service is 138 and session service is 139, so 138 is not the name service. DHCP uses 67 for the server and 68 for the client, so do not read the two ports simply as "server to client" and "client to server".
The ports you will see most, in a little more depth
Ports 80 and 443: web traffic
HTTP on port 80 sends everything in cleartext. HTTPS on port 443 wraps the same HTTP inside TLS, so a person on the same Wi-Fi cannot read your passwords. Most sites now redirect port 80 to 443. You will still see 80 open, mainly to perform that redirect.
Port 22: SSH
SSH is how administrators log in to Linux servers, copy files with SCP or SFTP, and tunnel other traffic. It is also the most attacked port on the internet, because every automated scanner tries it. Use key-based login, disable password login for root, and consider restricting access by source IP.
Port 53: DNS
Without DNS, nothing works by name. Most lookups are one UDP packet out and one back. When a reply is too big, or when a secondary DNS server copies a zone from a primary (a zone transfer), TCP is used. This is why blocking TCP 53 at a firewall can cause strange, intermittent failures.
Ports 25, 587, 110, 143: email
SMTP moves mail between servers (25) and from your mail client to your provider (587). POP3 and IMAP let you read it. If you configure a mail client, choose the encrypted variants (995 and 993) when your provider supports them.
Port 445: SMB
SMB shares files in Windows networks. It should almost never be reachable from the internet. Old SMB versions have been abused by worms in the past, so keep systems patched and disable SMBv1.
Port 3389: RDP
RDP gives a full desktop on a Windows machine. Exposing it directly to the internet is a common way for servers to get compromised through password guessing. Put it behind a VPN or a gateway and enable multi-factor authentication.
How to see which ports are open on your own machine
You do not need special tools to learn this. Run these on a computer you own.
# Linux: show listening TCP and UDP sockets with the owning process
sudo ss -tulpn
# Windows (Command Prompt as administrator): listening ports with process IDs
netstat -ano | findstr LISTENING
# Check whether one port on a host you are allowed to test is reachable
nc -zv 192.168.1.10 22
In the ss output, 0.0.0.0:22 means SSH is listening on every network interface. 127.0.0.1:3306 means MySQL is listening only on the local machine, which is much safer. That one detail, which address a service binds to, matters as much as the port number itself.
To scan a network from outside, administrators use Nmap, described in the Nmap reference guide. Scan only systems you own or have written permission to test. In India, unauthorised access to a computer system is an offence under the Information Technology Act, 2000, whatever the intent.
Why ports matter for security
- Firewalls work on ports. A rule such as "allow TCP 443 inbound to the web server, deny everything else" is the basis of most network security.
- Open ports are attack surface. A service that is listening can be probed, so a forgotten test database on 3306 is a real risk.
- Unusual ports are clues. A server making outbound connections to an odd port, or a workstation suddenly listening on a high port, deserves a look in incident response.
- Changing a port is not security. Moving SSH to port 2222 reduces log noise from bots, but a scanner finds it in seconds. Real protection comes from keys, patching and access control.
Common mistakes beginners make
- Thinking a port is a physical socket. It is only a number in the packet header.
- Memorising port numbers without protocols. "DNS is 53" is incomplete; you need "UDP and TCP".
- Confusing a port being open with a service being safe. Open means something is listening, not that it is configured securely.
- Forgetting that firewalls can block a port even when the service is running, so the service looks "down" from outside.
- Ignoring the bind address. A database on
0.0.0.0is exposed in a way that one on127.0.0.1is not.
Next steps
Learn the table above, then check your own machine with ss -tulpn and explain every line. For a longer list that includes ports used in security work, read the extended TCP and UDP ports list, and for the transport protocols themselves see the difference between TCP and UDP. If you want structured practice with routers, switches and protocols, the CCNA 200-301 course builds this from the ground up.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0