Top 20 Common Network Ports and Their Functions: A Beginner's Guide

Learn the top 20 most commonly used network ports, their protocols (TCP/UDP), and functions like HTTP, SSH, FTP, DNS, and more. Ideal for networking, cybersecurity, and IT beginners.

Jul 02, 2025 - 11:46
Updated: 2 days ago
106.9k
Top 20 Common Network Ports and Their Functions: A Beginner's Guide

Quick answer: A network port is a 16-bit number (0 to 65535) that tells a device which service should receive incoming traffic. The most common ports are 22 (SSH), 25 (SMTP), 53 (DNS), 80 (HTTP), 443 (HTTPS), 3306 (MySQL) and 3389 (RDP). Together with the IP address and protocol (TCP or UDP), the port identifies one conversation.

Key takeaways

  • An IP address finds the machine; the port finds the program on that machine. Both are needed for a connection.
  • Ports 0 to 1023 are well-known, 1024 to 49151 are registered, and 49152 to 65535 are dynamic (used by clients for temporary connections).
  • Some services use TCP, some UDP, some both. DNS uses UDP for most queries and TCP for large replies and zone transfers.
  • Cleartext services (Telnet 23, FTP 21, POP3 110) should be replaced by encrypted ones (SSH, SFTP, POP3S or IMAPS).
  • Every open port is attack surface. Know what is listening on your machines, and close what you do not need.

What is a network port?

A port is a number that a computer uses to sort incoming network traffic between its programs. Your laptop may run a browser, a mail client and an SSH session at the same time. All three share one IP address, so the operating system uses port numbers to hand each packet to the right program.

Think of an office building. The IP address is the building's street address. The port is the room number. A visitor needs both to reach the right person.

A single connection is identified by five values: source IP, source port, destination IP, destination port and protocol. When your browser opens a website, it connects from a random high port on your side (say 51514) to port 443 on the server. That is why thousands of people can all talk to the same server's port 443 at once without their traffic mixing.

The three port ranges

Port numbers are split into three ranges, as set out in RFC 6335 and maintained in the IANA service name and port number registry.

RangeNameWhat it is for
0 to 1023System (well-known) portsStandard services such as SSH, HTTP and DNS. On Linux, only a privileged process can listen on these.
1024 to 49151Registered (user) portsApplications registered with IANA, such as MySQL (3306) and RDP (3389).
49152 to 65535Dynamic (ephemeral) portsTemporary source ports chosen by the client for each outgoing connection.

Linux and Windows do not both use exactly the 49152 to 65535 range for ephemeral ports. Linux commonly uses 32768 to 60999. You can check with cat /proc/sys/net/ipv4/ip_local_port_range. This is a detail, but it matters when you read firewall logs.

20 common network ports and what they do

This table lists the ports you will meet most often in networking, system administration and security work. Learn it the way you learn multiplication tables: by repetition, then by using it.

PortProtocolServiceWhat it does
20TCPFTP dataCarries file data in active-mode FTP
21TCPFTP controlFTP login and commands; sends passwords in cleartext
22TCPSSHEncrypted remote login; also used by SFTP and SCP
23TCPTelnetRemote login with no encryption; avoid it
25TCPSMTPMail transfer between mail servers
53UDP and TCPDNSTurns names into IP addresses; TCP for large replies and zone transfers
67UDPDHCP serverThe DHCP server listens here
68UDPDHCP clientThe DHCP client listens here for the server's reply
69UDPTFTPSimple file transfer with no login; used for network device boot and config
80TCPHTTPUnencrypted web traffic
110TCPPOP3Downloads email; cleartext unless wrapped in TLS (POP3S uses 995)
123UDPNTPKeeps clocks synchronised
137 to 139UDP and TCPNetBIOS137 UDP name service, 138 UDP datagram service, 139 TCP session service (legacy Windows networking)
143TCPIMAPReads email on the server; IMAPS uses 993
161UDPSNMPNetwork monitoring queries; traps go to 162
443TCPHTTPSWeb traffic encrypted with TLS
445TCPSMBWindows file and printer sharing
587TCPSMTP submissionMail clients send outgoing mail to their server, normally with authentication and STARTTLS
3306TCPMySQLMySQL and MariaDB database connections
3389TCPRDPWindows Remote Desktop

Two points to get right in port tables. NetBIOS name service is port 137, datagram service is 138 and session service is 139, so 138 is not the name service. DHCP uses 67 for the server and 68 for the client, so do not read the two ports simply as "server to client" and "client to server".

The ports you will see most, in a little more depth

Ports 80 and 443: web traffic

HTTP on port 80 sends everything in cleartext. HTTPS on port 443 wraps the same HTTP inside TLS, so a person on the same Wi-Fi cannot read your passwords. Most sites now redirect port 80 to 443. You will still see 80 open, mainly to perform that redirect.

Port 22: SSH

SSH is how administrators log in to Linux servers, copy files with SCP or SFTP, and tunnel other traffic. It is also the most attacked port on the internet, because every automated scanner tries it. Use key-based login, disable password login for root, and consider restricting access by source IP.

Port 53: DNS

Without DNS, nothing works by name. Most lookups are one UDP packet out and one back. When a reply is too big, or when a secondary DNS server copies a zone from a primary (a zone transfer), TCP is used. This is why blocking TCP 53 at a firewall can cause strange, intermittent failures.

Ports 25, 587, 110, 143: email

SMTP moves mail between servers (25) and from your mail client to your provider (587). POP3 and IMAP let you read it. If you configure a mail client, choose the encrypted variants (995 and 993) when your provider supports them.

Port 445: SMB

SMB shares files in Windows networks. It should almost never be reachable from the internet. Old SMB versions have been abused by worms in the past, so keep systems patched and disable SMBv1.

Port 3389: RDP

RDP gives a full desktop on a Windows machine. Exposing it directly to the internet is a common way for servers to get compromised through password guessing. Put it behind a VPN or a gateway and enable multi-factor authentication.

How to see which ports are open on your own machine

You do not need special tools to learn this. Run these on a computer you own.

# Linux: show listening TCP and UDP sockets with the owning process
sudo ss -tulpn

# Windows (Command Prompt as administrator): listening ports with process IDs
netstat -ano | findstr LISTENING

# Check whether one port on a host you are allowed to test is reachable
nc -zv 192.168.1.10 22

In the ss output, 0.0.0.0:22 means SSH is listening on every network interface. 127.0.0.1:3306 means MySQL is listening only on the local machine, which is much safer. That one detail, which address a service binds to, matters as much as the port number itself.

To scan a network from outside, administrators use Nmap, described in the Nmap reference guide. Scan only systems you own or have written permission to test. In India, unauthorised access to a computer system is an offence under the Information Technology Act, 2000, whatever the intent.

Why ports matter for security

  • Firewalls work on ports. A rule such as "allow TCP 443 inbound to the web server, deny everything else" is the basis of most network security.
  • Open ports are attack surface. A service that is listening can be probed, so a forgotten test database on 3306 is a real risk.
  • Unusual ports are clues. A server making outbound connections to an odd port, or a workstation suddenly listening on a high port, deserves a look in incident response.
  • Changing a port is not security. Moving SSH to port 2222 reduces log noise from bots, but a scanner finds it in seconds. Real protection comes from keys, patching and access control.

Common mistakes beginners make

  • Thinking a port is a physical socket. It is only a number in the packet header.
  • Memorising port numbers without protocols. "DNS is 53" is incomplete; you need "UDP and TCP".
  • Confusing a port being open with a service being safe. Open means something is listening, not that it is configured securely.
  • Forgetting that firewalls can block a port even when the service is running, so the service looks "down" from outside.
  • Ignoring the bind address. A database on 0.0.0.0 is exposed in a way that one on 127.0.0.1 is not.

Next steps

Learn the table above, then check your own machine with ss -tulpn and explain every line. For a longer list that includes ports used in security work, read the extended TCP and UDP ports list, and for the transport protocols themselves see the difference between TCP and UDP. If you want structured practice with routers, switches and protocols, the CCNA 200-301 course builds this from the ground up.

Related reading

Frequently Asked Questions

A network port is a 16-bit number that identifies a specific service or process on a device. The IP address finds the machine and the port finds the program, so one computer can run a web server, mail client and SSH session at once.

There are 65,536 port numbers, 0 to 65535, and port 0 is reserved. They are split into well-known (0-1023), registered (1024-49151) and dynamic or private (49152-65535) ranges, each for different kinds of use.

Port 80 carries HTTP, the unencrypted version of web traffic. Most sites now use it only to redirect visitors to HTTPS on port 443, because anything sent over port 80 can be read by someone on the network path.

Port 443 carries HTTPS, which is HTTP protected by TLS encryption. It is the standard port for secure web browsing, online banking, login pages and most APIs, and it should be open on any public web server.

DHCP (67, 68), TFTP (69), NTP (123) and SNMP (161) use UDP, and DNS (53) uses UDP for most queries. UDP is connectionless and faster to start, which suits short request and reply exchanges.

Changing it reduces log noise from automated bots, but it does not stop a determined scanner, which finds any open port in seconds. Real SSH security comes from key-based login, disabling password login and keeping the software patched.

On Linux, run sudo ss -tulpn to list listening ports with their processes. On Windows, run netstat -ano in an administrator Command Prompt. Only scan other machines you own or have written permission to test.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.