TCP UDP Ports Table

–click a port number to copy it
PortProtoServiceDescription
20tcp/udpftp-dataFile Transfer [Default Data]
21tcp/udpftpFile Transfer Protocol [Control]
22tcp/udpsshThe Secure Shell (SSH) Protocol
23tcp/udptelnetTelnet
25tcp/udpsmtpSimple Mail Transfer
53tcp/udpdomainDomain Name Server
67tcp/udpbootpsBootstrap Protocol Server
68tcp/udpbootpcBootstrap Protocol Client
69tcp/udptftpTrivial File Transfer
80tcp/udphttpWorld Wide Web HTTP
88tcp/udpkerberosKerberos
110tcp/udppop3Post Office Protocol - Version 3
111tcp/udpsunrpcSUN Remote Procedure Call
113tcp/udpidentident
119tcp/udpnntpNetwork News Transfer Protocol
123tcp/udpntpNetwork Time Protocol
135tcp/udpepmapDCE endpoint resolution
137tcp/udpnetbios-nsNETBIOS Name Service
138tcp/udpnetbios-dgmNETBIOS Datagram Service
139tcp/udpnetbios-ssnNETBIOS Session Service
143tcpimapInternet Message Access Protocol
161tcp/udpsnmpSNMP
162tcp/udpsnmptrapSNMPTRAP
179tcp/udpbgpBorder Gateway Protocol
194tcp/udpircInternet Relay Chat Protocol
389tcp/udpldapLightweight Directory Access Protocol
443tcp/udphttpshttp protocol over TLS/SSL
445tcp/udpmicrosoft-dsMicrosoft-DS
464tcp/udpkpasswdkpasswd
465tcp/udpurdURL Rendezvous Directory for SSM
514tcp/udpshellcmd like exec, but automatic authentication is performed as
515tcp/udpprinterspooler
530tcp/udpcourierrpc
531tcp/udpconferencechat
532tcp/udpnetnewsreadnews
540tcp/udpuucpuucpd
548tcp/udpafpovertcpAFP over TCP
554tcp/udprtspReal Time Streaming Protocol (RTSP)
587tcp/udpsubmissionMessage Submission
631tcp/udpippIPP (Internet Printing Protocol)
636tcp/udpldapsldap protocol over TLS/SSL (was sldap)
646tcp/udpldpLDP
691tcp/udpmsexch-routingMS Exchange Routing
860tcp/udpiscsiiSCSI
873tcp/udprsyncrsync
902tcp/udpideafarm-doorself documenting Telnet Door
989tcp/udpftps-dataftp protocol, data, over TLS/SSL
990tcp/udpftpsftp protocol, control, over TLS/SSL
992tcp/udptelnetstelnet protocol over TLS/SSL
993tcpimapsIMAP over TLS protocol
995tcp/udppop3sPOP3 over TLS protocol
1080tcp/udpsocksSocks
1194tcp/udpopenvpnOpenVPN
1433tcp/udpms-sql-sMicrosoft-SQL-Server
1521tcp/udpncube-lmnCube License Manager
1723tcp/udppptppptp
2049tcp/udpshilpshilp
2082tcp/udpinfowaveInfowave Mobility Server
2083tcp/udpradsecSecure Radius Service
2181tcp/udpeforwardeforward
2375tcpdockerDocker REST API (plain text)
2376tcpdocker-sDocker REST API (ssl)
2377tcpswarmRPC interface for Docker Swarm
2483tcp/udpttcOracle TTC
2484tcp/udpttc-sslOracle TTC SSL
3000tcp/udphbciHBCI
3128tcp/udpndl-aasActive API Server Port
3268tcp/udpmsft-gcMicrosoft Global Catalog
3269tcp/udpmsft-gc-sslMicrosoft Global Catalog with LDAP/SSL
3306tcp/udpmysqlMySQL
3389tcp/udpms-wbt-serverMS WBT Server
4444tcp/udpkrb524KRB524
5000tcp/udpcommplex-maincommplex-main
5060tcp/udpsipSIP
5061tcp/udpsipsSIP-TLS
5222tcpxmpp-clientXMPP Client Connection
5353tcp/udpmdnsMulticast DNS
5432tcp/udppostgresqlPostgreSQL Database
5555tcp/udppersonal-agentPersonal Agent
5666tcpnrpeNagios Remote Plugin Executor
5672tcp/udpamqpAMQP
5900tcp/udprfbRemote Framebuffer
5984tcp/udpcouchdbCouchDB
5985tcp/udpwsmanWBEM WS-Management HTTP
6379tcpredisAn advanced key-value cache and store
6443tcp/udpsun-sr-httpsService Registry Default HTTPS Domain
6667tcpIRC(de facto) Internet Relay Chat - community standard, never registered with IANA
8000tcp/udpirdmiiRDMI
8008tcp/udphttp-altHTTP Alternate
8009tcpnvme-discNVMe over Fabrics Discovery Service
8080tcp/udphttp-altHTTP Alternate (see port 80)
8081tcp/udpsunproxyadminSun Proxy Admin Service
8443tcp/udppcsync-httpsPCsync HTTPS
8888tcp/udpddi-tcp-1NewsEDGE server TCP (TCP 1)
9000tcp/udpcslistenerCSlistener
9090tcp/udpwebsmWebSM
9200tcp/udpwap-wspWAP connectionless session service
9300tcp/udpvraceVirtual Racing Service
11211tcp/udpmemcacheMemory cache service
15672tcprabbitmq-mgmt(de facto) RabbitMQ management UI - de facto, not in the registry
16379tcpredis-cluster(de facto) Redis Cluster bus - de facto convention
25565tcpminecraft(de facto) Minecraft Java server - de facto, absent from IANA
27017tcpmongodbMongo database system
27018tcpmongodb-shard(de facto) MongoDB sharded cluster member - de facto
50070tcphadoop-namenode(de facto) Hadoop HDFS NameNode UI - de facto
61616tcpactivemq(de facto) Apache ActiveMQ broker - de facto
Every row is verified against the official IANA service name and port number registry; the handful of rows marked "de facto" (Minecraft 25565, IRC 6667) are community conventions the registry never assigned. Below 1024 lies the well-known range where binding needs root, 49152-65535 is the dynamic range your OS hands out as source ports. Bottom line: a port number is just a convention until both sides agree - blocking 80 and 443 kills a website, while 3306 open to the world is how databases leak. Network companions: HTTP status codes table, HTTP headers table, DNS records table and IPv4 subnet cheatsheet.

Every network connection ends in a port number, and the same few dozen ports explain almost everything: 80 and 443 for the web, 22 for SSH, 53 for DNS, 3306 for MySQL, 6379 for Redis, 25565 for Minecraft. This table covers the 106 ports you actually meet in logs, firewall rules and docker-compose files - each verified against the IANA registry, with the community conventions IANA never assigned labeled as de facto.

The structure is simple and worth internalizing: 0-1023 is the well-known range where binding historically required administrator rights, 1024-49151 is the registered range for vendor-assigned services, and 49152-65535 is the dynamic pool your OS draws ephemeral source ports from - which is why scanning the top of the range finds noise, not services.

How to use

  1. Type a port, service or product to filter - '443', 'mysql', 'docker' and '27017' all find their rows.
  2. Click any port number to copy it for firewall rules, security groups and config files.
  3. Watch the Proto column: most services speak both TCP and UDP, but the ones that matter (HTTP, databases) are TCP-only in practice.

Frequently asked questions

Why do some well-known services have no official IANA entry?

The registry is a formal process with a designated allocator; popular community software often skips it and wins by adoption instead. Minecraft's 25565, IRC's 6667 and RabbitMQ's management port 15672 are de facto standards - documented in vendor docs, expected by every tutorial, but formally unassigned. That gap is exactly why the table labels them: a compliance audit cares about the registry, a network engineer cares about reality.

What is the difference between TCP and UDP on the same port number?

They are separate namespaces: TCP 53 and UDP 53 are different channels, and both exist for DNS because zone transfers want TCP reliability while lookups want UDP speed. The protocol column shows which transports each service registered. Firewalls treat them independently too - allowing TCP 443 does nothing for QUIC, which rides UDP 443 and needs its own rule.

Why is binding to ports below 1024 special?

The well-known range inherited a Unix privilege convention: binding required root so users could not impersonate system services. Modern Linux ships with unprivileged_port_start tuned lower, and containers routinely bind 80 as a non-root process with capabilities - but the convention still shapes defaults, and confusing errors like permission denied on port 80 almost always trace back to it.

Can two services share one port?

On the same transport, no: one TCP 443 listener per interface is the rule, which is why reverse proxies exist - nginx or a load balancer owns 443 and routes by hostname (SNI) to internal services on unexposed ports. The table shows sibling services on 8080/8443 for exactly this pattern: application servers hiding behind a proxy that speaks the public port.

Related tools