TCP/UDP Port Lookup

From vendor documentation

Search TCP, UDP and SCTP port assignments by number, service name or purpose, with the IANA or vendor source and a confidence marker on every row.

Search

166 port assignments on record

A number is matched exactly (179 → BGP only). Anything else searches the service name, purpose, aliases and category.

Sort direction

Export

166 row(s) currently shown

Where the data comes from

verified rows are stable IANA service registrations. documented rows are vendor conventions such as Oracle on 1521 or Redis on 6379 — real, widely deployed, but not the registered service name. needs-validation rows are community-reported and should be confirmed on your own estate.

Results

Showing 166 of 166 assignments

Matching rows
166
Total in table
166
Query mode
Browse all
ConfidenceCopy
7tcp/udpechoEchoes every octet back to the sender. A debugging relic; almost always disabled in production.General / infrastructureverified
9tcp/udpdiscardSilently discards anything sent to it. Occasionally useful for MTU probing.General / infrastructureverified
13tcp/udpdaytimeReturns the current date and time as ASCII. Superseded by NTP.General / infrastructureverified
19tcp/udpchargenStreams a repeating character pattern. A classic reflected-DDoS amplifier — block it at the edge.General / infrastructureverified
20tcpftp-dataFTP data channel in active mode: the server connects back from this port to the client.File transfer & sharingverified
21tcpftpFTP control channel: credentials, commands and directory listings travel here in clear text.File transfer & sharingverified
22tcp/udpsshSecure Shell: encrypted remote CLI, file copy (SCP/SFTP) and port forwarding.Management & monitoringverified
23tcp/udptelnetCleartext remote terminal. Still found on console servers and old switches; never across an untrusted link.Management & monitoringverified
25tcpsmtpSMTP relay between mail servers. Most consumer ISPs block outbound 25; use 587 for submission.Mailverified
37tcp/udptimeSeconds since 1900-01-01 UTC. Obsoleted by NTP (123/udp).General / infrastructureverified
43tcpnicnameWHOIS directory lookups for domains, IP allocations and AS numbers.General / infrastructureverified
49tcp/udptacacsTACACS/TACACS+ device administration AAA. TACACS+ encrypts the whole body, not just the password.Authentication & AAAverified
53tcp/udpdomainDNS. Queries are UDP; zone transfers (AXFR/IXFR) and answers over 512 bytes fall back to TCP.General / infrastructureverified
67udpbootpsDHCP/BOOTP server side: receives client broadcasts and answers with an address lease.General / infrastructureverified
68udpbootpcDHCP/BOOTP client side: the address the client is still trying to obtain.General / infrastructureverified
69udptftpTrivial FTP: lock-step UDP transfer used to push IOS images and configurations to devices.File transfer & sharingverified
79tcpfingerUser information lookup. Historically leaked account names; should be filtered.General / infrastructureverified
80tcphttpWorld Wide Web HTTP. Also used by many device web UIs and by captive-portal redirects.Web & HTTPverified
88tcp/udpkerberosKerberos KDC ticket granting. UDP for small tickets, TCP once the reply outgrows the datagram.Authentication & AAAverified
110tcppop3Post Office Protocol v3 mailbox retrieval. Plaintext unless wrapped in TLS on 995.Mailverified
111tcp/udpsunrpcONC RPC portmapper: tells a client which ephemeral port an NFS/NIS service is listening on.File transfer & sharingverified
113tcpidentIdent/Auth: legacy IRC-era check of which user owns a TCP connection.General / infrastructureverified
119tcpnntpUsenet news transfer and reading.General / infrastructureverified
123udpntpNetwork Time Protocol. Operates over UDP only for normal clock sync.General / infrastructureverified
135tcp/udpmsrpcMicrosoft RPC endpoint mapper — the Windows equivalent of portmapper. Frequently scanned.General / infrastructureverified
137udpnetbios-nsNetBIOS name service: legacy Windows/ Samba name resolution on a broadcast segment.File transfer & sharingverified
138udpnetbios-dgmNetBIOS datagram service: browser elections and legacy broadcast messaging.File transfer & sharingverified
139tcpnetbios-ssnNetBIOS session service: pre-SMB-2000 file sharing and print sharing.File transfer & sharingverified
143tcpimapIMAP4 mailbox access. Clients keep the mail on the server; the TLS variant is 993.Mailverified
161udpsnmpSNMP polling: the management station asks, the device answers. v3 adds authentication and privacy.Management & monitoringverified
162udpsnmptrapSNMP traps and informs: the device pushes an event to the collector without being asked.Management & monitoringverified
179tcpbgpBorder Gateway Protocol: the inter-domain routing protocol that carries the global routing table.Routing & control planeverified
389tcp/udpldapLDAP directory access in cleartext; also the port used by StartTLS upgrade attempts.Authentication & AAAverified
443tcphttpsHTTP over TLS. The default for web, device management and most modern APIs. QUIC uses 443/udp.Web & HTTPverified
445tcpmicrosoft-dsSMB directly over TCP: modern Windows file sharing, printing and remote registry.File transfer & sharingverified
464tcp/udpkpasswdKerberos password change (kadmin/changepw).Authentication & AAAverified
465tcpsubmissionsSMTP over implicit TLS — the original "smtps" port, now the standard for authenticated submission.Mailverified
500udpisakmpIKE phase 1 and 2 negotiation for IPsec. UDP 500 only while NAT-T is not yet detected.Tunnelling & VPNverified
512tcpexecrexec: remote command execution with a cleartext password. Obsolete and dangerous.General / infrastructureverified
513tcploginrlogin: remote login trusting the source address. Superseded by SSH.General / infrastructureverified
513udpwhoShows which users are logged in on a host. Same number as rlogin but a different protocol.General / infrastructureverified
514tcpshellrsh: remote shell without a password prompt. Same number as syslog but a different protocol.General / infrastructureverified
514udpsyslogClassic BSD syslog export: unacknowledged, unfragmented UDP datagrams to a collector.Management & monitoringverified
515tcpprinterLPD/LPR line printer spooler. Still enabled on many network printers.General / infrastructureverified
517udptalknfs-era interactive chat between two logged-in users.General / infrastructureverified
518udpntalkNewer variant of the talk protocol.General / infrastructureverified
520udprouterRIPv1/v2: distance-vector routing updates, sent as UDP broadcasts or multicasts.Routing & control planeverified
521udpripngRIP next generation: the IPv6 variant of RIP, multicast to ff02::9.Routing & control planeverified
546udpdhcpv6-clientDHCPv6 client side. Uses the same relay and multicast rules as 547 but the opposite direction.General / infrastructureverified
547udpdhcpv6-serverDHCPv6 server and relay side: address assignment, prefix delegation and stateless options.General / infrastructureverified
548tcpafpovertcpApple Filing Protocol over TCP — the classic Mac file sharing service.File transfer & sharingverified
554tcp/udprtspReal Time Streaming Protocol: controls IP cameras and streaming media sessions.Voice & real-time mediaverified
587tcpsubmissionMessage submission for authenticated users, with STARTTLS. The port mail clients should use.Mailverified
623udpasf-rmcpIPMI over LAN (RMCP): out-of-band server management, power control and console redirection.Management & monitoringverified
631tcp/udpippInternet Printing Protocol, the modern replacement for LPD and the CUPS default.General / infrastructureverified
636tcp/udpldapsLDAP over implicit TLS. Widely used by appliances that cannot negotiate StartTLS.Authentication & AAAverified
646tcp/udpldpLabel Distribution Protocol: MPLS label binding between directly connected routers (RFC 5036).Routing & control planeverified
830tcpnetconf-sshNETCONF over SSH: model-driven configuration and telemetry (RFC 6242).Management & monitoringverified
853tcp/udpdomain-sDNS over TLS. TCP for DoT sessions; the UDP assignment exists but is rarely deployed.General / infrastructureverified
860tcpiscsiiSCSI target discovery and session establishment. The data path then uses port 3260.Datacenter fabric & storageverified
861tcp/udpowamp-controlOne-way active measurement protocol control channel for latency and jitter measurement.General / infrastructureverified
873tcprsyncrsync daemon mode: file synchronisation over a native protocol, unencrypted unless tunnelled.File transfer & sharingverified
902tcp/udpvmware-authdVMware ESXi/vCenter management and remote console authentication. Not an IANA VMware assignment.Datacenter fabric & storagedocumented
989tcpftps-dataFTP data channel protected by implicit TLS.File transfer & sharingverified
990tcpftpsFTP control channel protected by implicit TLS. Many appliances only support explicit (AUTH TLS) mode.File transfer & sharingverified
993tcpimapsIMAP over implicit TLS. The default for almost every modern mail client.Mailverified
995tcppop3sPOP3 over implicit TLS.Mailverified
1080tcpsocksSOCKS proxy: relays arbitrary TCP streams and, in SOCKS5, UDP associations.Tunnelling & VPNdocumented
1194udpopenvpnOpenVPN default port. UDP mode is preferred; TCP 443 mode exists to defeat blocking.Tunnelling & VPNdocumented
1433tcpms-sql-sMicrosoft SQL Server. The first packet of a connection is the TDS pre-login handshake.Database, cache & searchverified
1434tcp/udpms-sql-mSQL Server browser/monitor service. UDP 1434 answers instance-enumeration probes.Database, cache & searchverified
1521tcporacleOracle TNS listener. IANA registers 1521 as "ncube-lm"; Oracle has used it for decades by convention.Database, cache & searchdocumented
1645udpradiusLegacy RADIUS authentication port from the pre-RFC 2865 drafts. Still seen on old NAS configs.Authentication & AAAneeds-validation
1646udpradius-acctLegacy RADIUS accounting port. Superseded by 1813; a common cause of silent accounting failures.Authentication & AAAneeds-validation
1701udpl2tpLayer 2 Tunnelling Protocol control and data. Usually paired with IPsec ESP for confidentiality.Tunnelling & VPNverified
1719udph323gatestatH.323 gatekeeper RAS: registration, admission and status for VoIP gateways.Voice & real-time mediaverified
1720tcph323hostcallH.323 call signalling (Q.931 over TCP). Media then flows over dynamically negotiated RTP ports.Voice & real-time mediaverified
1723tcppptpPoint-to-Point Tunnelling Protocol control channel. MS-CHAPv2 is broken — treat as legacy only.Tunnelling & VPNverified
1812udpradiusRADIUS authentication and authorisation. The shared secret is the only integrity protection.Authentication & AAAverified
1813udpradius-acctRADIUS accounting: session start, interim updates and stop records for billing and auditing.Authentication & AAAverified
1883tcpmqttMQTT broker for IoT and telemetry. Plaintext; use 8883 with TLS in production.General / infrastructureverified
1900udpssdpSimple Service Discovery Protocol: UPnP multicast announcements and discovery on 239.255.255.250.General / infrastructureverified
1985udphsrpCisco Hot Standby Router Protocol: first-hop redundancy hellos to 224.0.0.2.Routing & control planeverified
2000tcp/udpcisco-sccpSkinny Client Control Protocol: Cisco IP phone signalling to Unified Communications Manager.Voice & real-time mediaverified
2049tcp/udpnfsNetwork File System. v4 uses only 2049; v3 also needs portmapper 111 plus a pile of dynamic ports.File transfer & sharingverified
2123udpgtp-controlGPRS Tunnelling Protocol control plane (Gn/Gp): creates, modifies and deletes mobile bearers.Datacenter fabric & storageverified
2152udpgtp-userGPRS Tunnelling Protocol user plane: carries subscriber IP packets inside the mobile core.Datacenter fabric & storageverified
2181tcpzookeeperApache ZooKeeper client port, used for cluster coordination by Kafka and HBase.Database, cache & searchdocumented
2375tcpdockerDocker daemon REST API, unencrypted and unauthenticated. Never expose this to a network.Management & monitoringdocumented
2376tcpdocker-sDocker daemon REST API over TLS with client-certificate authentication.Management & monitoringdocumented
2379tcpetcd-clientetcd client API — the datastore behind Kubernetes control planes.Management & monitoringdocumented
2380tcpetcd-serveretcd peer replication between cluster members.Management & monitoringdocumented
2427udpmgcp-gatewayMedia Gateway Control Protocol: a call agent drives a residential or trunk gateway.Voice & real-time mediaverified
2601tcpzebraFRR/Quagga zebra routing daemon management port on the loopback interface.Routing & control planedocumented
2605tcpbgpdFRR/Quagga BGP daemon management port on the loopback interface.Routing & control planedocumented
2727udpmgcp-callagentMGCP call agent side — the reverse direction of 2427.Voice & real-time mediaverified
2905sctpm3uaMTP3 User Adaptation over SCTP: carries SS7 signalling between softswitches.General / infrastructureverified
3000tcpgrafanaDe-facto development and dashboard port (Grafana, Node, Rails). Not an IANA assignment.Web & HTTPdocumented
3050tcpgds-dbFirebird/InterBase database server (gds_db).Database, cache & searchverified
3128tcpsquid-httpSquid caching proxy default. IANA registers 3128 to a different service (ndl-aas).Tunnelling & VPNdocumented
3260tcpiscsi-targetiSCSI target portal: SCSI commands and data over TCP for block storage over IP.Datacenter fabric & storageverified
3306tcpmysqlMySQL / MariaDB protocol. Percona XtraDB Cluster also uses it for replication traffic.Database, cache & searchverified
3389tcp/udpms-wbt-serverMicrosoft Remote Desktop (RDP). UDP is used for the newer RemoteFX/UDP transport.Management & monitoringverified
3478tcp/udpstunSTUN/TURN: NAT traversal and relay for WebRTC and SIP. TURN relaying also uses 3478.Voice & real-time mediaverified
3479udpstun-behaviorSTUN behaviour discovery (RFC 5780) — the follow-up probe that classifies a NAT.Voice & real-time mediaverified
3702tcp/udpws-discoveryWS-Discovery multicast probing: ONVIF cameras, printers and Windows network discovery.General / infrastructureverified
3784tcp/udpbfd-controlBidirectional Forwarding Detection: single-hop control packets (RFC 5881).Routing & control planeverified
3785udpbfd-echoBFD echo mode: the neighbour loops the packet back, so no session state is needed on it.Routing & control planeverified
3868sctpdiameterDiameter over SCTP — the transport preferred inside telecom core networks.Authentication & AAAverified
3868tcpdiameterDiameter over TCP: the AAA successor to RADIUS for mobile and IMS networks.Authentication & AAAverified
4190tcpmanagesieveManageSieve: uploads server-side mail filtering rules from a mail client.Mailverified
4500udpipsec-nat-tIPsec NAT traversal: ESP-in-UDP encapsulation once a NAT is detected, plus IKE on the same port.Tunnelling & VPNverified
4784udpbfd-multihopBFD control packets for multihop and multipoint sessions (RFC 5883). IANA name: bfd-multi-ctl.Routing & control planeverified
4786tcpsmart-installCisco Smart Install director. Historically exploited; Cisco recommends disabling it outright.Management & monitoringdocumented
4789udpvxlanVXLAN: MAC-in-UDP overlay encapsulation. The IANA-assigned port — Linux historically defaulted to 8472.Datacenter fabric & storageverified
5004udpavt-profile-1RTP media data stream (profile 1). Even/odd pairing with 5005 is a convention, not a rule.Voice & real-time mediaverified
5005udpavt-profile-2RTCP control stream: reception reports, jitter and loss statistics for the 5004 session.Voice & real-time mediaverified
5060tcp/udpsipSIP signalling: call setup, registration and presence. UDP is the classic transport.Voice & real-time mediaverified
5061tcp/udpsipsSIP over TLS: encrypted signalling. Note that the media (RTP) is still separate and unencrypted by default.Voice & real-time mediaverified
5222tcpxmpp-clientXMPP client-to-server connections, and the older Google Cloud Messaging push channel.General / infrastructureverified
5269tcpxmpp-serverXMPP server-to-server federation between domains.General / infrastructureverified
5349tcp/udpstunsSTUN/TURN over TLS and DTLS.Voice & real-time mediaverified
5353udpmdnsMulticast DNS (Bonjour): zero-configuration name resolution on 224.0.0.251 and ff02::fb.General / infrastructureverified
5355tcp/udpllmnrLink-Local Multicast Name Resolution — the Windows counterpart to mDNS. A popular spoofing target.General / infrastructureverified
5432tcppostgresqlPostgreSQL protocol. The first message from the client is a StartupMessage or an SSLRequest.Database, cache & searchverified
5666tcpnrpeNagios Remote Plugin Executor: runs checks on a monitored host. Not an IANA assignment.Management & monitoringdocumented
5672tcp/udpamqpAdvanced Message Queuing Protocol: the RabbitMQ broker default.General / infrastructureverified
5900tcp/udprfbVirtual Network Computing (VNC) remote framebuffer. Displays 1..n follow on 5901, 5902 and so on.Management & monitoringverified
5938tcp/udpteamviewerTeamViewer remote support. Falls back to 443 when outbound ports are restricted.Management & monitoringdocumented
5984tcpcouchdbApache CouchDB HTTP API and its cluster replication endpoints.Database, cache & searchdocumented
5985tcpwsmanWindows Remote Management over HTTP — PowerShell Remoting. Plaintext; prefer 5986.Management & monitoringverified
5986tcpwsmansWindows Remote Management over TLS.Management & monitoringverified
6081udpgeneveGeneric Network Virtualisation Encapsulation: a VXLAN alternative with extensible TLVs.Datacenter fabric & storageverified
6379tcpredisRedis. Unauthenticated by default, and the CONFIG command can write files — never expose it.Database, cache & searchdocumented
6443tcpkubernetes-apiKubernetes API server. IANA registers 6443 as "sun-sr-https"; the kube-apiserver claims it by convention.Management & monitoringdocumented
6633tcpopenflow-legacyOpenFlow before 1.4 — the original controller/target port. Now superseded by 6653.Routing & control planeneeds-validation
6640tcp/udpovsdbOpen vSwitch database management protocol — how a controller configures virtual switches.Datacenter fabric & storagedocumented
6653tcp/udpopenflowOpenFlow switch/controller channel from protocol version 1.4 onward.Routing & control planeverified
8000tcpirdmiGeneric HTTP alternate, widely used by development servers, cameras and appliance web UIs.Web & HTTPverified
8008tcphttp-altAlternative HTTP port, sometimes used by Google Cast and embedded device UIs.Web & HTTPverified
8080tcphttp-altThe universal secondary HTTP port: proxies, Tomcat, appliance UIs and API gateways.Web & HTTPverified
8081tcpsunproxyadminIANA name is sunproxyadmin, but the port is overwhelmingly reused as a second HTTP listener.Web & HTTPdocumented
8086tcpinfluxdbInfluxDB HTTP API and the Chronograf UI.Database, cache & searchdocumented
8291tcpwinboxMikroTik Winbox management and RouterOS MAC-level discovery. Frequently targeted by botnets.Management & monitoringdocumented
8443tcppcsync-httpsThe standard secondary HTTPS port: appliance management UIs, Kubernetes dashboards and API gateways.Web & HTTPverified
8472udpvxlan-linuxThe Linux kernel VXLAN default (before the IANA 4789 assignment). Mismatched ports silently black-hole overlays.Datacenter fabric & storagedocumented
8883tcpsecure-mqttMQTT over TLS — the port IoT brokers should actually be using.General / infrastructureverified
9000tcpcslistenerIANA name cslistener; in practice PHP-FPM, SonarQube, Portainer and MinIO all default here.Web & HTTPdocumented
9042tcpcassandraApache Cassandra native binary protocol (CQL) client port.Database, cache & searchdocumented
9090tcpprometheusPrometheus server UI/API and Cockpit. IANA registers 9090 as "websm".Management & monitoringdocumented
9092tcpkafkaApache Kafka broker listener for producer and consumer traffic.General / infrastructuredocumented
9100tcphp-pdl-datastrRaw printing (JetDirect/AppSocket). Also used by Prometheus node_exporter in modern stacks.General / infrastructureverified
9200tcpelasticsearchElasticsearch REST API. Historically unauthenticated — a classic accidental data exposure.Database, cache & searchdocumented
9443tcptungsten-httpsIANA name tungsten-https; commonly a second HTTPS listener for container dashboards.Web & HTTPdocumented
10050tcpzabbix-agentZabbix agent passive checks: the server connects to the agent.Management & monitoringdocumented
10051tcpzabbix-trapperZabbix server trapper: agents and senders push items into the server.Management & monitoringdocumented
10161tcp/udpsnmpdtlsSNMP over DTLS/TLS (SNMPv3 with the DTLS transport model).Management & monitoringverified
10162tcp/udpsnmpdtls-trapSNMP notifications over DTLS/TLS.Management & monitoringverified
10250tcpkubelet-apiKubernetes kubelet API: exec, logs and metrics endpoints. Unauthenticated by default in old builds.Management & monitoringdocumented
10255tcpkubelet-read-onlyKubernetes kubelet read-only port, removed in recent releases but still found in the wild.Management & monitoringdocumented
11211tcp/udpmemcacheMemcached. No authentication and a huge UDP amplification factor — keep it on the loopback or a private segment.Database, cache & searchverified
15672tcprabbitmq-managementRabbitMQ management HTTP API and web UI.Management & monitoringdocumented
26257tcpcockroachdbCockroachDB SQL and intra-cluster gossip between nodes.Database, cache & searchdocumented
27017tcp/udpmongodMongoDB server. Older releases shipped without authentication — a recurring breach headline.Database, cache & searchdocumented
50000tcp/udpdb2IBM Db2 database server and its command-line client connections.Database, cache & searchverified
51820udpwireguardWireGuard VPN default listen port. Kernel-side, UDP only, and silent to unauthenticated probes.Tunnelling & VPNdocumented

Frequently asked

Which port does BGP use?
BGP uses TCP port 179. IANA registers it for TCP (and SCTP), both eBGP and iBGP default to it, and a firewall has to permit it between peers in both directions.
Why are there two RADIUS port pairs?
RADIUS authentication and accounting were first assigned UDP 1645 and 1646. RFC 2865 and RFC 2866 moved them to 1812 and 1813 to avoid an earlier clash. Configurations that mix the two pairs authenticate correctly but silently drop accounting records.
Is VXLAN port 8472 or 4789?
IANA assigned 4789. The Linux kernel defaulted to 8472 before that, and both are still deployed, which is why two VXLAN implementations can report a healthy tunnel while passing no traffic to each other.
Why do 514/tcp and 514/udp show different services?
Because they are different services that happen to share a number: UDP 514 is syslog export, TCP 514 is the legacy rsh remote shell. That is why this table keys on the port and transport pair, not the port alone.
Is anything sent anywhere when I search?
No. The table ships with the page and the search runs in your browser. The page makes no network requests at all.

Next