Port Reference - Free Online Network Reference Tool | IconVault
Search 130 common network ports by number, service or protocol. Port, protocol, service and security note with click to copy. Free and client-side.
Port Reference
130 common ports with protocol, service and security notes
| Port | Proto | Service | Security note |
|---|---|---|---|
| 20 | TCP | FTP data | Plaintext file transfer; prefer SFTP/SCP. |
| 21 | TCP | FTP control | Credentials sent in cleartext; avoid on public nets. |
| 22 | TCP | SSH | Keep patched, use keys, rate-limit brute force attempts. |
| 23 | TCP | Telnet | Legacy and fully plaintext; disable, use SSH. |
| 25 | TCP | SMTP | Watch for open relay; most providers block outbound 25. |
| 49 | TCP/UDP | TACACS+ | Device authentication; keep off public internet. |
| 53 | TCP/UDP | DNS | Common for amplification attacks; restrict recursion. |
| 67 | UDP | DHCP server | Rogue DHCP servers enable MITM; use snooping. |
| 68 | UDP | DHCP client | Client-side only; no inbound rule needed. |
| 69 | UDP | TFTP | No authentication at all; never expose publicly. |
| 79 | TCP | Finger | Leaks user info; almost always disabled today. |
| 80 | TCP | HTTP | Plaintext web; redirect everything to 443. |
| 88 | TCP/UDP | Kerberos | Windows/AD auth; restrict to domain network. |
| 110 | TCP | POP3 | Plaintext mail retrieval; prefer 995. |
| 111 | TCP/UDP | RPCbind | Frequent attack target; firewall aggressively. |
| 113 | TCP | Ident | Legacy user lookup; usually safe to drop. |
| 119 | TCP | NNTP | Usenet news; plaintext. |
| 123 | UDP | NTP | Used in reflection attacks; use authenticated NTP. |
| 135 | TCP | MS RPC | Windows RPC endpoint mapper; never expose to internet. |
| 137 | UDP | NetBIOS Name | Leaks machine info; block at perimeter. |
| 138 | UDP | NetBIOS Datagram | Legacy Windows networking; disable with 137/139. |
| 139 | TCP | NetBIOS Session | Old SMB over NetBIOS; prefer SMB3 on 445. |
| 143 | TCP | IMAP | Plaintext mail access; prefer 993. |
| 161 | UDP | SNMP | Change default community strings; prefer SNMPv3. |
| 162 | UDP | SNMP trap | Inbound traps; whitelist senders. |
| 179 | TCP | BGP | Router peering; authenticate sessions. |
| 194 | TCP | IRC | Chat relay; plaintext, historically botnet C2. |
| 389 | TCP/UDP | LDAP | Directory lookups; prefer LDAPS on 636. |
| 427 | TCP/UDP | SLP | Service discovery; can leak device details. |
| 443 | TCP | HTTPS | Encrypted web; keep TLS configs current. |
| 445 | TCP | SMB | Ransomware favorite; never expose to internet. |
| 465 | TCP | SMTPS | Legacy implicit TLS mail submission. |
| 500 | UDP | IKE (IPsec) | VPN key exchange; restrict to VPN endpoints. |
| 512 | TCP | rexec | Legacy remote exec; disable. |
| 513 | TCP | rlogin | Legacy, trusts hosts; disable, use SSH. |
| 514 | UDP | Syslog | Plaintext logs in transit; prefer TLS syslog. |
| 515 | TCP | LPD print | Printer protocol; restrict to LAN. |
| 520 | UDP | RIP | Legacy routing protocol; authenticate if used. |
| 546 | UDP | DHCPv6 client | Client-side only. |
| 547 | UDP | DHCPv6 server | Restrict like DHCPv4. |
| 548 | TCP | AFP | Apple file sharing; largely replaced by SMB. |
| 554 | TCP | RTSP | Camera/stream control; often weak default creds. |
| 587 | TCP | SMTP submission | Authenticated mail send with STARTTLS. |
| 593 | TCP | HTTP RPC | Windows RPC over HTTP; restrict. |
| 623 | UDP | IPMI | Out-of-band management; isolate on mgmt VLAN. |
| 631 | TCP | IPP / CUPS | Printing; expose only where needed. |
| 636 | TCP | LDAPS | LDAP over TLS; preferred over 389. |
| 646 | TCP | LDP | MPLS label distribution; carrier networks. |
| 989 | TCP | FTPS data | FTP over TLS data channel. |
| 990 | TCP | FTPS control | FTP over TLS control channel. |
| 993 | TCP | IMAPS | IMAP over TLS; preferred over 143. |
| 995 | TCP | POP3S | POP3 over TLS; preferred over 110. |
| 1080 | TCP | SOCKS proxy | Often abused as open proxy; authenticate. |
| 1099 | TCP | RMI registry | Java RMI; restrict, deserialization attacks. |
| 1194 | TCP/UDP | OpenVPN | VPN default; keep server updated. |
| 1241 | TCP | Nessus | Vulnerability scanner console; restrict access. |
| 1311 | TCP | Dell OpenManage | Server management UI; isolate. |
| 1433 | TCP | SQL Server | Prime brute-force target; never expose directly. |
| 1434 | UDP | SQL Server Browser | Used in reflection attacks; block externally. |
| 1521 | TCP | Oracle DB | Restrict to app servers; audit listeners. |
| 1701 | UDP | L2TP | Usually paired with IPsec. |
| 1720 | TCP | H.323 | VoIP signaling; restrict to voice VLAN. |
| 1723 | TCP | PPTP | Broken crypto; do not use for VPN anymore. |
| 1812 | UDP | RADIUS auth | Network auth; protect shared secrets. |
| 1813 | UDP | RADIUS accounting | Usage records; protect like 1812. |
| 1900 | UDP | SSDP | UPnP discovery; reflection abuse, disable if unused. |
| 2049 | TCP | NFS | Restrict exports; v4 with Kerberos preferred. |
| 2082 | TCP | cPanel | Hosting panel; enforce 2FA. |
| 2083 | TCP | cPanel HTTPS | Secure cPanel; still enforce 2FA. |
| 2086 | TCP | WHM | Hosting admin; restrict by IP. |
| 2087 | TCP | WHM HTTPS | Secure WHM; restrict by IP. |
| 2095 | TCP | cPanel webmail | Prefer the HTTPS variant 2096. |
| 2096 | TCP | cPanel webmail HTTPS | Encrypted webmail access. |
| 2181 | TCP | ZooKeeper | No auth by default; bind to localhost/cluster. |
| 2375 | TCP | Docker API | Unauthenticated root access; NEVER expose. |
| 2376 | TCP | Docker API TLS | TLS-protected Docker; use mutual TLS. |
| 2379 | TCP | etcd client | K8s data store; restrict to cluster. |
| 2380 | TCP | etcd peer | Cluster-only traffic. |
| 3000 | TCP | Dev servers | Node/Rails dev default; not for production. |
| 3268 | TCP | AD Global Catalog | Domain-joined networks only. |
| 3306 | TCP | MySQL/MariaDB | Brute-force target; bind to app hosts only. |
| 3389 | TCP | RDP | Top ransomware vector; use VPN + MFA. |
| 3493 | TCP | NUT UPS | UPS monitoring; LAN only. |
| 3690 | TCP | Subversion | Version control; prefer SSH transport. |
| 4369 | TCP | EPMD (Erlang) | RabbitMQ/Elixir node discovery; restrict. |
| 4500 | UDP | IPsec NAT-T | VPN traversal; pair with 500. |
| 4789 | UDP | VXLAN | Overlay networking; data-center fabric only. |
| 47808 | UDP | BACnet | Building automation; isolate OT networks. |
| 5000 | TCP | Flask / dev | Dev default; debug mode is remote code exec. |
| 5060 | TCP/UDP | SIP | VoIP signaling; toll-fraud target. |
| 5061 | TCP | SIPS | SIP over TLS; preferred over 5060. |
| 5353 | UDP | mDNS | Local discovery; can leak hostnames. |
| 5432 | TCP | PostgreSQL | Restrict to app servers; strong passwords. |
| 5601 | TCP | Kibana | ES dashboard; enable auth + TLS. |
| 5672 | TCP | AMQP (RabbitMQ) | Message broker; restrict to producers. |
| 5900 | TCP | VNC | Weak auth historically; tunnel over SSH. |
| 5984 | TCP | CouchDB | Enable admin party off; require auth. |
| 5985 | TCP | WinRM HTTP | Windows remote mgmt; prefer 5986. |
| 5986 | TCP | WinRM HTTPS | Encrypted WinRM; still restrict. |
| 6379 | TCP | Redis | No auth by default; bind to localhost. |
| 6443 | TCP | Kubernetes API | Cluster crown jewels; RBAC + TLS. |
| 6667 | TCP | IRC | Chat; plaintext, botnet C2 history. |
| 7000 | TCP | Cassandra | Inter-node gossip; cluster only. |
| 8000 | TCP | Alt HTTP | Common dev/alt web port. |
| 8008 | TCP | Alt HTTP | Proxy/alt web traffic. |
| 8009 | TCP | Tomcat AJP | Ghostcat CVE-2020-1938; update/disable. |
| 8020 | TCP | HDFS NameNode | Hadoop internals; cluster only. |
| 8080 | TCP | HTTP proxy / alt | Often admin UIs; authenticate. |
| 8088 | TCP | Hadoop YARN | Cluster only; RCE history. |
| 830 | TCP | NETCONF | Network device config over SSH. |
| 8443 | TCP | HTTPS alt | Alt TLS web; same hardening as 443. |
| 9000 | TCP | PHP-FPM / SonarQube | Restrict; debug endpoints leak. |
| 9042 | TCP | Cassandra CQL | Client queries; authenticate. |
| 9092 | TCP | Kafka | Broker; enable SASL/TLS. |
| 9200 | TCP | Elasticsearch | No auth by default; bind to localhost. |
| 9300 | TCP | ES transport | Cluster traffic only. |
| 9870 | TCP | HDFS web UI | Hadoop UI; restrict. |
| 9987 | UDP | TeamSpeak | Voice server default. |
| 10000 | TCP | Webmin | Server admin UI; restrict + 2FA. |
| 10250 | TCP | kubelet | K8s node agent; restrict. |
| 10251 | TCP | kube-scheduler | K8s internals; cluster only. |
| 10252 | TCP | kube-controller | K8s internals; cluster only. |
| 11211 | TCP/UDP | Memcached | UDP reflection abuse; disable UDP, bind local. |
| 15672 | TCP | RabbitMQ mgmt | Change default guest creds. |
| 25565 | TCP | Minecraft | Game server default. |
| 27015 | TCP/UDP | Source games | Valve game server default. |
| 27017 | TCP | MongoDB | Ransomware wiped open DBs; enable auth. |
| 32400 | TCP | Plex | Media server; use Plex auth. |
| 61616 | TCP | ActiveMQ | Message broker; restrict console. |
| 64738 | TCP/UDP | Mumble | Voice chat server. |
Click any row to copy the port number. 130 ports listed.
About this tool
IconVault's Port Reference is a searchable table of 130 well-known and registered ports, covering the classics like 22 (SSH), 80 (HTTP) and 443 (HTTPS) through databases, messaging systems, game servers and DevOps infrastructure. Every row lists the port number, protocol, service name and a practical security note, and clicking any row copies the port number to your clipboard.
It is free and runs fully in your browser, with instant filtering as you type. The honest limit: this is a reference, not a scanner. It cannot tell you which ports are open on your machine or anyone else's, and a handful of rows cover the most common services, not the full IANA registry.
Frequently asked questions
Popular searches
More tools
IPv4 Converter
Convert IPv4 to integer, hex, binary, octal and IPv6-mapped
IPv6 ULA Generator
Random RFC 4193 private IPv6 prefixes in one click
MAC Generator
Random MAC addresses with OUI presets and vendor lookup
Random Port
Secure random port numbers with no duplicates
Coming soon
CLI
Coming soon
Figma plugin
Coming soon
VS Code extension
Coming soon
Chrome extension
Coming soon
AI icon generator
Coming soon
Team workspaces
Coming soon