TCP/UDP Port Lookup
From vendor documentationSearch TCP, UDP and SCTP port assignments by number, service name or purpose, with the IANA or vendor source and a confidence marker on every row.
Search
166 port assignments on record
A number is matched exactly (179 → BGP only). Anything else searches the service name, purpose, aliases and category.
Sort direction
Export
166 row(s) currently shown
Where the data comes from
verified rows are stable IANA service registrations. documented rows are vendor conventions such as Oracle on 1521 or Redis on 6379 — real, widely deployed, but not the registered service name. needs-validation rows are community-reported and should be confirmed on your own estate.
Results
Showing 166 of 166 assignments
- Matching rows
- 166
- Total in table
- 166
- Query mode
- Browse all
| Confidence | Copy | |||||
|---|---|---|---|---|---|---|
| 7 | tcp/udp | echo | Echoes every octet back to the sender. A debugging relic; almost always disabled in production. | General / infrastructure | verified | |
| 9 | tcp/udp | discard | Silently discards anything sent to it. Occasionally useful for MTU probing. | General / infrastructure | verified | |
| 13 | tcp/udp | daytime | Returns the current date and time as ASCII. Superseded by NTP. | General / infrastructure | verified | |
| 19 | tcp/udp | chargen | Streams a repeating character pattern. A classic reflected-DDoS amplifier — block it at the edge. | General / infrastructure | verified | |
| 20 | tcp | ftp-data | FTP data channel in active mode: the server connects back from this port to the client. | File transfer & sharing | verified | |
| 21 | tcp | ftp | FTP control channel: credentials, commands and directory listings travel here in clear text. | File transfer & sharing | verified | |
| 22 | tcp/udp | ssh | Secure Shell: encrypted remote CLI, file copy (SCP/SFTP) and port forwarding. | Management & monitoring | verified | |
| 23 | tcp/udp | telnet | Cleartext remote terminal. Still found on console servers and old switches; never across an untrusted link. | Management & monitoring | verified | |
| 25 | tcp | smtp | SMTP relay between mail servers. Most consumer ISPs block outbound 25; use 587 for submission. | verified | ||
| 37 | tcp/udp | time | Seconds since 1900-01-01 UTC. Obsoleted by NTP (123/udp). | General / infrastructure | verified | |
| 43 | tcp | nicname | WHOIS directory lookups for domains, IP allocations and AS numbers. | General / infrastructure | verified | |
| 49 | tcp/udp | tacacs | TACACS/TACACS+ device administration AAA. TACACS+ encrypts the whole body, not just the password. | Authentication & AAA | verified | |
| 53 | tcp/udp | domain | DNS. Queries are UDP; zone transfers (AXFR/IXFR) and answers over 512 bytes fall back to TCP. | General / infrastructure | verified | |
| 67 | udp | bootps | DHCP/BOOTP server side: receives client broadcasts and answers with an address lease. | General / infrastructure | verified | |
| 68 | udp | bootpc | DHCP/BOOTP client side: the address the client is still trying to obtain. | General / infrastructure | verified | |
| 69 | udp | tftp | Trivial FTP: lock-step UDP transfer used to push IOS images and configurations to devices. | File transfer & sharing | verified | |
| 79 | tcp | finger | User information lookup. Historically leaked account names; should be filtered. | General / infrastructure | verified | |
| 80 | tcp | http | World Wide Web HTTP. Also used by many device web UIs and by captive-portal redirects. | Web & HTTP | verified | |
| 88 | tcp/udp | kerberos | Kerberos KDC ticket granting. UDP for small tickets, TCP once the reply outgrows the datagram. | Authentication & AAA | verified | |
| 110 | tcp | pop3 | Post Office Protocol v3 mailbox retrieval. Plaintext unless wrapped in TLS on 995. | verified | ||
| 111 | tcp/udp | sunrpc | ONC RPC portmapper: tells a client which ephemeral port an NFS/NIS service is listening on. | File transfer & sharing | verified | |
| 113 | tcp | ident | Ident/Auth: legacy IRC-era check of which user owns a TCP connection. | General / infrastructure | verified | |
| 119 | tcp | nntp | Usenet news transfer and reading. | General / infrastructure | verified | |
| 123 | udp | ntp | Network Time Protocol. Operates over UDP only for normal clock sync. | General / infrastructure | verified | |
| 135 | tcp/udp | msrpc | Microsoft RPC endpoint mapper — the Windows equivalent of portmapper. Frequently scanned. | General / infrastructure | verified | |
| 137 | udp | netbios-ns | NetBIOS name service: legacy Windows/ Samba name resolution on a broadcast segment. | File transfer & sharing | verified | |
| 138 | udp | netbios-dgm | NetBIOS datagram service: browser elections and legacy broadcast messaging. | File transfer & sharing | verified | |
| 139 | tcp | netbios-ssn | NetBIOS session service: pre-SMB-2000 file sharing and print sharing. | File transfer & sharing | verified | |
| 143 | tcp | imap | IMAP4 mailbox access. Clients keep the mail on the server; the TLS variant is 993. | verified | ||
| 161 | udp | snmp | SNMP polling: the management station asks, the device answers. v3 adds authentication and privacy. | Management & monitoring | verified | |
| 162 | udp | snmptrap | SNMP traps and informs: the device pushes an event to the collector without being asked. | Management & monitoring | verified | |
| 179 | tcp | bgp | Border Gateway Protocol: the inter-domain routing protocol that carries the global routing table. | Routing & control plane | verified | |
| 389 | tcp/udp | ldap | LDAP directory access in cleartext; also the port used by StartTLS upgrade attempts. | Authentication & AAA | verified | |
| 443 | tcp | https | HTTP over TLS. The default for web, device management and most modern APIs. QUIC uses 443/udp. | Web & HTTP | verified | |
| 445 | tcp | microsoft-ds | SMB directly over TCP: modern Windows file sharing, printing and remote registry. | File transfer & sharing | verified | |
| 464 | tcp/udp | kpasswd | Kerberos password change (kadmin/changepw). | Authentication & AAA | verified | |
| 465 | tcp | submissions | SMTP over implicit TLS — the original "smtps" port, now the standard for authenticated submission. | verified | ||
| 500 | udp | isakmp | IKE phase 1 and 2 negotiation for IPsec. UDP 500 only while NAT-T is not yet detected. | Tunnelling & VPN | verified | |
| 512 | tcp | exec | rexec: remote command execution with a cleartext password. Obsolete and dangerous. | General / infrastructure | verified | |
| 513 | tcp | login | rlogin: remote login trusting the source address. Superseded by SSH. | General / infrastructure | verified | |
| 513 | udp | who | Shows which users are logged in on a host. Same number as rlogin but a different protocol. | General / infrastructure | verified | |
| 514 | tcp | shell | rsh: remote shell without a password prompt. Same number as syslog but a different protocol. | General / infrastructure | verified | |
| 514 | udp | syslog | Classic BSD syslog export: unacknowledged, unfragmented UDP datagrams to a collector. | Management & monitoring | verified | |
| 515 | tcp | printer | LPD/LPR line printer spooler. Still enabled on many network printers. | General / infrastructure | verified | |
| 517 | udp | talk | nfs-era interactive chat between two logged-in users. | General / infrastructure | verified | |
| 518 | udp | ntalk | Newer variant of the talk protocol. | General / infrastructure | verified | |
| 520 | udp | router | RIPv1/v2: distance-vector routing updates, sent as UDP broadcasts or multicasts. | Routing & control plane | verified | |
| 521 | udp | ripng | RIP next generation: the IPv6 variant of RIP, multicast to ff02::9. | Routing & control plane | verified | |
| 546 | udp | dhcpv6-client | DHCPv6 client side. Uses the same relay and multicast rules as 547 but the opposite direction. | General / infrastructure | verified | |
| 547 | udp | dhcpv6-server | DHCPv6 server and relay side: address assignment, prefix delegation and stateless options. | General / infrastructure | verified | |
| 548 | tcp | afpovertcp | Apple Filing Protocol over TCP — the classic Mac file sharing service. | File transfer & sharing | verified | |
| 554 | tcp/udp | rtsp | Real Time Streaming Protocol: controls IP cameras and streaming media sessions. | Voice & real-time media | verified | |
| 587 | tcp | submission | Message submission for authenticated users, with STARTTLS. The port mail clients should use. | verified | ||
| 623 | udp | asf-rmcp | IPMI over LAN (RMCP): out-of-band server management, power control and console redirection. | Management & monitoring | verified | |
| 631 | tcp/udp | ipp | Internet Printing Protocol, the modern replacement for LPD and the CUPS default. | General / infrastructure | verified | |
| 636 | tcp/udp | ldaps | LDAP over implicit TLS. Widely used by appliances that cannot negotiate StartTLS. | Authentication & AAA | verified | |
| 646 | tcp/udp | ldp | Label Distribution Protocol: MPLS label binding between directly connected routers (RFC 5036). | Routing & control plane | verified | |
| 830 | tcp | netconf-ssh | NETCONF over SSH: model-driven configuration and telemetry (RFC 6242). | Management & monitoring | verified | |
| 853 | tcp/udp | domain-s | DNS over TLS. TCP for DoT sessions; the UDP assignment exists but is rarely deployed. | General / infrastructure | verified | |
| 860 | tcp | iscsi | iSCSI target discovery and session establishment. The data path then uses port 3260. | Datacenter fabric & storage | verified | |
| 861 | tcp/udp | owamp-control | One-way active measurement protocol control channel for latency and jitter measurement. | General / infrastructure | verified | |
| 873 | tcp | rsync | rsync daemon mode: file synchronisation over a native protocol, unencrypted unless tunnelled. | File transfer & sharing | verified | |
| 902 | tcp/udp | vmware-authd | VMware ESXi/vCenter management and remote console authentication. Not an IANA VMware assignment. | Datacenter fabric & storage | documented | |
| 989 | tcp | ftps-data | FTP data channel protected by implicit TLS. | File transfer & sharing | verified | |
| 990 | tcp | ftps | FTP control channel protected by implicit TLS. Many appliances only support explicit (AUTH TLS) mode. | File transfer & sharing | verified | |
| 993 | tcp | imaps | IMAP over implicit TLS. The default for almost every modern mail client. | verified | ||
| 995 | tcp | pop3s | POP3 over implicit TLS. | verified | ||
| 1080 | tcp | socks | SOCKS proxy: relays arbitrary TCP streams and, in SOCKS5, UDP associations. | Tunnelling & VPN | documented | |
| 1194 | udp | openvpn | OpenVPN default port. UDP mode is preferred; TCP 443 mode exists to defeat blocking. | Tunnelling & VPN | documented | |
| 1433 | tcp | ms-sql-s | Microsoft SQL Server. The first packet of a connection is the TDS pre-login handshake. | Database, cache & search | verified | |
| 1434 | tcp/udp | ms-sql-m | SQL Server browser/monitor service. UDP 1434 answers instance-enumeration probes. | Database, cache & search | verified | |
| 1521 | tcp | oracle | Oracle TNS listener. IANA registers 1521 as "ncube-lm"; Oracle has used it for decades by convention. | Database, cache & search | documented | |
| 1645 | udp | radius | Legacy RADIUS authentication port from the pre-RFC 2865 drafts. Still seen on old NAS configs. | Authentication & AAA | needs-validation | |
| 1646 | udp | radius-acct | Legacy RADIUS accounting port. Superseded by 1813; a common cause of silent accounting failures. | Authentication & AAA | needs-validation | |
| 1701 | udp | l2tp | Layer 2 Tunnelling Protocol control and data. Usually paired with IPsec ESP for confidentiality. | Tunnelling & VPN | verified | |
| 1719 | udp | h323gatestat | H.323 gatekeeper RAS: registration, admission and status for VoIP gateways. | Voice & real-time media | verified | |
| 1720 | tcp | h323hostcall | H.323 call signalling (Q.931 over TCP). Media then flows over dynamically negotiated RTP ports. | Voice & real-time media | verified | |
| 1723 | tcp | pptp | Point-to-Point Tunnelling Protocol control channel. MS-CHAPv2 is broken — treat as legacy only. | Tunnelling & VPN | verified | |
| 1812 | udp | radius | RADIUS authentication and authorisation. The shared secret is the only integrity protection. | Authentication & AAA | verified | |
| 1813 | udp | radius-acct | RADIUS accounting: session start, interim updates and stop records for billing and auditing. | Authentication & AAA | verified | |
| 1883 | tcp | mqtt | MQTT broker for IoT and telemetry. Plaintext; use 8883 with TLS in production. | General / infrastructure | verified | |
| 1900 | udp | ssdp | Simple Service Discovery Protocol: UPnP multicast announcements and discovery on 239.255.255.250. | General / infrastructure | verified | |
| 1985 | udp | hsrp | Cisco Hot Standby Router Protocol: first-hop redundancy hellos to 224.0.0.2. | Routing & control plane | verified | |
| 2000 | tcp/udp | cisco-sccp | Skinny Client Control Protocol: Cisco IP phone signalling to Unified Communications Manager. | Voice & real-time media | verified | |
| 2049 | tcp/udp | nfs | Network File System. v4 uses only 2049; v3 also needs portmapper 111 plus a pile of dynamic ports. | File transfer & sharing | verified | |
| 2123 | udp | gtp-control | GPRS Tunnelling Protocol control plane (Gn/Gp): creates, modifies and deletes mobile bearers. | Datacenter fabric & storage | verified | |
| 2152 | udp | gtp-user | GPRS Tunnelling Protocol user plane: carries subscriber IP packets inside the mobile core. | Datacenter fabric & storage | verified | |
| 2181 | tcp | zookeeper | Apache ZooKeeper client port, used for cluster coordination by Kafka and HBase. | Database, cache & search | documented | |
| 2375 | tcp | docker | Docker daemon REST API, unencrypted and unauthenticated. Never expose this to a network. | Management & monitoring | documented | |
| 2376 | tcp | docker-s | Docker daemon REST API over TLS with client-certificate authentication. | Management & monitoring | documented | |
| 2379 | tcp | etcd-client | etcd client API — the datastore behind Kubernetes control planes. | Management & monitoring | documented | |
| 2380 | tcp | etcd-server | etcd peer replication between cluster members. | Management & monitoring | documented | |
| 2427 | udp | mgcp-gateway | Media Gateway Control Protocol: a call agent drives a residential or trunk gateway. | Voice & real-time media | verified | |
| 2601 | tcp | zebra | FRR/Quagga zebra routing daemon management port on the loopback interface. | Routing & control plane | documented | |
| 2605 | tcp | bgpd | FRR/Quagga BGP daemon management port on the loopback interface. | Routing & control plane | documented | |
| 2727 | udp | mgcp-callagent | MGCP call agent side — the reverse direction of 2427. | Voice & real-time media | verified | |
| 2905 | sctp | m3ua | MTP3 User Adaptation over SCTP: carries SS7 signalling between softswitches. | General / infrastructure | verified | |
| 3000 | tcp | grafana | De-facto development and dashboard port (Grafana, Node, Rails). Not an IANA assignment. | Web & HTTP | documented | |
| 3050 | tcp | gds-db | Firebird/InterBase database server (gds_db). | Database, cache & search | verified | |
| 3128 | tcp | squid-http | Squid caching proxy default. IANA registers 3128 to a different service (ndl-aas). | Tunnelling & VPN | documented | |
| 3260 | tcp | iscsi-target | iSCSI target portal: SCSI commands and data over TCP for block storage over IP. | Datacenter fabric & storage | verified | |
| 3306 | tcp | mysql | MySQL / MariaDB protocol. Percona XtraDB Cluster also uses it for replication traffic. | Database, cache & search | verified | |
| 3389 | tcp/udp | ms-wbt-server | Microsoft Remote Desktop (RDP). UDP is used for the newer RemoteFX/UDP transport. | Management & monitoring | verified | |
| 3478 | tcp/udp | stun | STUN/TURN: NAT traversal and relay for WebRTC and SIP. TURN relaying also uses 3478. | Voice & real-time media | verified | |
| 3479 | udp | stun-behavior | STUN behaviour discovery (RFC 5780) — the follow-up probe that classifies a NAT. | Voice & real-time media | verified | |
| 3702 | tcp/udp | ws-discovery | WS-Discovery multicast probing: ONVIF cameras, printers and Windows network discovery. | General / infrastructure | verified | |
| 3784 | tcp/udp | bfd-control | Bidirectional Forwarding Detection: single-hop control packets (RFC 5881). | Routing & control plane | verified | |
| 3785 | udp | bfd-echo | BFD echo mode: the neighbour loops the packet back, so no session state is needed on it. | Routing & control plane | verified | |
| 3868 | sctp | diameter | Diameter over SCTP — the transport preferred inside telecom core networks. | Authentication & AAA | verified | |
| 3868 | tcp | diameter | Diameter over TCP: the AAA successor to RADIUS for mobile and IMS networks. | Authentication & AAA | verified | |
| 4190 | tcp | managesieve | ManageSieve: uploads server-side mail filtering rules from a mail client. | verified | ||
| 4500 | udp | ipsec-nat-t | IPsec NAT traversal: ESP-in-UDP encapsulation once a NAT is detected, plus IKE on the same port. | Tunnelling & VPN | verified | |
| 4784 | udp | bfd-multihop | BFD control packets for multihop and multipoint sessions (RFC 5883). IANA name: bfd-multi-ctl. | Routing & control plane | verified | |
| 4786 | tcp | smart-install | Cisco Smart Install director. Historically exploited; Cisco recommends disabling it outright. | Management & monitoring | documented | |
| 4789 | udp | vxlan | VXLAN: MAC-in-UDP overlay encapsulation. The IANA-assigned port — Linux historically defaulted to 8472. | Datacenter fabric & storage | verified | |
| 5004 | udp | avt-profile-1 | RTP media data stream (profile 1). Even/odd pairing with 5005 is a convention, not a rule. | Voice & real-time media | verified | |
| 5005 | udp | avt-profile-2 | RTCP control stream: reception reports, jitter and loss statistics for the 5004 session. | Voice & real-time media | verified | |
| 5060 | tcp/udp | sip | SIP signalling: call setup, registration and presence. UDP is the classic transport. | Voice & real-time media | verified | |
| 5061 | tcp/udp | sips | SIP over TLS: encrypted signalling. Note that the media (RTP) is still separate and unencrypted by default. | Voice & real-time media | verified | |
| 5222 | tcp | xmpp-client | XMPP client-to-server connections, and the older Google Cloud Messaging push channel. | General / infrastructure | verified | |
| 5269 | tcp | xmpp-server | XMPP server-to-server federation between domains. | General / infrastructure | verified | |
| 5349 | tcp/udp | stuns | STUN/TURN over TLS and DTLS. | Voice & real-time media | verified | |
| 5353 | udp | mdns | Multicast DNS (Bonjour): zero-configuration name resolution on 224.0.0.251 and ff02::fb. | General / infrastructure | verified | |
| 5355 | tcp/udp | llmnr | Link-Local Multicast Name Resolution — the Windows counterpart to mDNS. A popular spoofing target. | General / infrastructure | verified | |
| 5432 | tcp | postgresql | PostgreSQL protocol. The first message from the client is a StartupMessage or an SSLRequest. | Database, cache & search | verified | |
| 5666 | tcp | nrpe | Nagios Remote Plugin Executor: runs checks on a monitored host. Not an IANA assignment. | Management & monitoring | documented | |
| 5672 | tcp/udp | amqp | Advanced Message Queuing Protocol: the RabbitMQ broker default. | General / infrastructure | verified | |
| 5900 | tcp/udp | rfb | Virtual Network Computing (VNC) remote framebuffer. Displays 1..n follow on 5901, 5902 and so on. | Management & monitoring | verified | |
| 5938 | tcp/udp | teamviewer | TeamViewer remote support. Falls back to 443 when outbound ports are restricted. | Management & monitoring | documented | |
| 5984 | tcp | couchdb | Apache CouchDB HTTP API and its cluster replication endpoints. | Database, cache & search | documented | |
| 5985 | tcp | wsman | Windows Remote Management over HTTP — PowerShell Remoting. Plaintext; prefer 5986. | Management & monitoring | verified | |
| 5986 | tcp | wsmans | Windows Remote Management over TLS. | Management & monitoring | verified | |
| 6081 | udp | geneve | Generic Network Virtualisation Encapsulation: a VXLAN alternative with extensible TLVs. | Datacenter fabric & storage | verified | |
| 6379 | tcp | redis | Redis. Unauthenticated by default, and the CONFIG command can write files — never expose it. | Database, cache & search | documented | |
| 6443 | tcp | kubernetes-api | Kubernetes API server. IANA registers 6443 as "sun-sr-https"; the kube-apiserver claims it by convention. | Management & monitoring | documented | |
| 6633 | tcp | openflow-legacy | OpenFlow before 1.4 — the original controller/target port. Now superseded by 6653. | Routing & control plane | needs-validation | |
| 6640 | tcp/udp | ovsdb | Open vSwitch database management protocol — how a controller configures virtual switches. | Datacenter fabric & storage | documented | |
| 6653 | tcp/udp | openflow | OpenFlow switch/controller channel from protocol version 1.4 onward. | Routing & control plane | verified | |
| 8000 | tcp | irdmi | Generic HTTP alternate, widely used by development servers, cameras and appliance web UIs. | Web & HTTP | verified | |
| 8008 | tcp | http-alt | Alternative HTTP port, sometimes used by Google Cast and embedded device UIs. | Web & HTTP | verified | |
| 8080 | tcp | http-alt | The universal secondary HTTP port: proxies, Tomcat, appliance UIs and API gateways. | Web & HTTP | verified | |
| 8081 | tcp | sunproxyadmin | IANA name is sunproxyadmin, but the port is overwhelmingly reused as a second HTTP listener. | Web & HTTP | documented | |
| 8086 | tcp | influxdb | InfluxDB HTTP API and the Chronograf UI. | Database, cache & search | documented | |
| 8291 | tcp | winbox | MikroTik Winbox management and RouterOS MAC-level discovery. Frequently targeted by botnets. | Management & monitoring | documented | |
| 8443 | tcp | pcsync-https | The standard secondary HTTPS port: appliance management UIs, Kubernetes dashboards and API gateways. | Web & HTTP | verified | |
| 8472 | udp | vxlan-linux | The Linux kernel VXLAN default (before the IANA 4789 assignment). Mismatched ports silently black-hole overlays. | Datacenter fabric & storage | documented | |
| 8883 | tcp | secure-mqtt | MQTT over TLS — the port IoT brokers should actually be using. | General / infrastructure | verified | |
| 9000 | tcp | cslistener | IANA name cslistener; in practice PHP-FPM, SonarQube, Portainer and MinIO all default here. | Web & HTTP | documented | |
| 9042 | tcp | cassandra | Apache Cassandra native binary protocol (CQL) client port. | Database, cache & search | documented | |
| 9090 | tcp | prometheus | Prometheus server UI/API and Cockpit. IANA registers 9090 as "websm". | Management & monitoring | documented | |
| 9092 | tcp | kafka | Apache Kafka broker listener for producer and consumer traffic. | General / infrastructure | documented | |
| 9100 | tcp | hp-pdl-datastr | Raw printing (JetDirect/AppSocket). Also used by Prometheus node_exporter in modern stacks. | General / infrastructure | verified | |
| 9200 | tcp | elasticsearch | Elasticsearch REST API. Historically unauthenticated — a classic accidental data exposure. | Database, cache & search | documented | |
| 9443 | tcp | tungsten-https | IANA name tungsten-https; commonly a second HTTPS listener for container dashboards. | Web & HTTP | documented | |
| 10050 | tcp | zabbix-agent | Zabbix agent passive checks: the server connects to the agent. | Management & monitoring | documented | |
| 10051 | tcp | zabbix-trapper | Zabbix server trapper: agents and senders push items into the server. | Management & monitoring | documented | |
| 10161 | tcp/udp | snmpdtls | SNMP over DTLS/TLS (SNMPv3 with the DTLS transport model). | Management & monitoring | verified | |
| 10162 | tcp/udp | snmpdtls-trap | SNMP notifications over DTLS/TLS. | Management & monitoring | verified | |
| 10250 | tcp | kubelet-api | Kubernetes kubelet API: exec, logs and metrics endpoints. Unauthenticated by default in old builds. | Management & monitoring | documented | |
| 10255 | tcp | kubelet-read-only | Kubernetes kubelet read-only port, removed in recent releases but still found in the wild. | Management & monitoring | documented | |
| 11211 | tcp/udp | memcache | Memcached. No authentication and a huge UDP amplification factor — keep it on the loopback or a private segment. | Database, cache & search | verified | |
| 15672 | tcp | rabbitmq-management | RabbitMQ management HTTP API and web UI. | Management & monitoring | documented | |
| 26257 | tcp | cockroachdb | CockroachDB SQL and intra-cluster gossip between nodes. | Database, cache & search | documented | |
| 27017 | tcp/udp | mongod | MongoDB server. Older releases shipped without authentication — a recurring breach headline. | Database, cache & search | documented | |
| 50000 | tcp/udp | db2 | IBM Db2 database server and its command-line client connections. | Database, cache & search | verified | |
| 51820 | udp | wireguard | WireGuard VPN default listen port. Kernel-side, UDP only, and silent to unauthenticated probes. | Tunnelling & VPN | documented |
Frequently asked
- Which port does BGP use?
- BGP uses TCP port 179. IANA registers it for TCP (and SCTP), both eBGP and iBGP default to it, and a firewall has to permit it between peers in both directions.
- Why are there two RADIUS port pairs?
- RADIUS authentication and accounting were first assigned UDP 1645 and 1646. RFC 2865 and RFC 2866 moved them to 1812 and 1813 to avoid an earlier clash. Configurations that mix the two pairs authenticate correctly but silently drop accounting records.
- Is VXLAN port 8472 or 4789?
- IANA assigned 4789. The Linux kernel defaulted to 8472 before that, and both are still deployed, which is why two VXLAN implementations can report a healthy tunnel while passing no traffic to each other.
- Why do 514/tcp and 514/udp show different services?
- Because they are different services that happen to share a number: UDP 514 is syslog export, TCP 514 is the legacy rsh remote shell. That is why this table keys on the port and transport pair, not the port alone.
- Is anything sent anywhere when I search?
- No. The table ships with the page and the search runs in your browser. The page makes no network requests at all.
Next
- IP Protocol NumbersEvery assigned IANA IP protocol number with its registry keyword and RFC — ICMP 1, TCP 6, UDP 17, GRE 47, ESP 50, OSPF 89, VRRP 112 — plus a bulk mode that names a pasted list of numbers.
- Protocol Header Overhead & MTUHeader sizes for every common encapsulation, plus a stack builder that turns Ethernet, VLAN, PPPoE, MPLS, GRE, IPsec, VXLAN, Geneve and SRv6 into a total, an effective MTU and the TCP MSS for IPv4 and IPv6.
- Vendor CLI Cross-ReferenceTwenty operational tasks — BGP summary, MAC table, LLDP, port mirroring, packet capture, save and diff — with the command for IOS, IOS-XE, IOS-XR, NX-OS, EOS, VRP, Comware and Junos side by side.