Kostenlos · Netzwerk & IT-Infrastruktur
TCP/UDP-Port-Suche.
Suchen Sie gängige TCP- und UDP-Ports nach Nummer, Dienst oder Kategorie, mit Sicherheitshinweisen zu Diensten, die nie ins Internet gehören.
Ports
| Port | Protocol | Service | Category | Security note |
|---|---|---|---|---|
| 20 | TCP | FTP data | files | Cleartext; prefer SFTP |
| 21 | TCP | FTP control | files | Cleartext credentials; prefer SFTP or FTPS |
| 22 | TCP | SSH, SFTP, SCP | remote | Restrict sources; use keys, not passwords |
| 23 | TCP | Telnet | remote | Cleartext; do not expose |
| 25 | TCP | SMTP (server to server) | Many ISPs block it outbound for home users | |
| 53 | TCP/UDP | DNS | core | Open resolvers are abused for amplification |
| 67 | UDP | DHCP server | core | |
| 68 | UDP | DHCP client | core | |
| 69 | UDP | TFTP | files | No authentication |
| 80 | TCP | HTTP | web | |
| 88 | TCP/UDP | Kerberos | windows | |
| 102 | TCP | Siemens S7 (ISO-TSAP) | industrial | Never expose industrial controllers |
| 110 | TCP | POP3 | Cleartext; prefer 995 | |
| 111 | TCP/UDP | rpcbind / portmapper | unix | Do not expose |
| 119 | TCP | NNTP | other | |
| 123 | UDP | NTP | core | Restrict monlist/mode 7 (amplification) |
| 135 | TCP | Microsoft RPC endpoint mapper | windows | Do not expose |
| 137 | UDP | NetBIOS name service | windows | Do not expose |
| 138 | UDP | NetBIOS datagram | windows | Do not expose |
| 139 | TCP | NetBIOS session (SMB over NetBIOS) | windows | Do not expose |
| 143 | TCP | IMAP | Cleartext; prefer 993 | |
| 161 | UDP | SNMP | monitoring | Use SNMPv3; v1/v2c community strings are cleartext |
| 162 | UDP | SNMP traps | monitoring | |
| 179 | TCP | BGP | routing | |
| 389 | TCP/UDP | LDAP | directory | Use LDAPS or StartTLS |
| 443 | TCP | HTTPS | web | |
| 443 | UDP | HTTP/3 (QUIC) | web | |
| 445 | TCP | SMB (file sharing) | windows | Do not expose to the internet |
| 464 | TCP/UDP | Kerberos password change | windows | |
| 465 | TCP | SMTP submission over TLS (SMTPS) | Preferred submission port (RFC 8314) | |
| 500 | UDP | IKE (IPsec VPN) | vpn | |
| 502 | TCP | Modbus TCP | industrial | No authentication; never expose |
| 514 | UDP | Syslog | monitoring | Cleartext |
| 515 | TCP | LPD printing | printing | |
| 520 | UDP | RIP | routing | |
| 546 | UDP | DHCPv6 client | core | |
| 547 | UDP | DHCPv6 server | core | |
| 548 | TCP | AFP (Apple file sharing) | files | |
| 554 | TCP/UDP | RTSP (camera streams) | media | Cameras often have weak passwords |
| 587 | TCP | SMTP submission (STARTTLS) | ||
| 623 | UDP | IPMI / BMC | remote | Do not expose; known weaknesses |
| 631 | TCP | IPP / CUPS printing | printing | |
| 636 | TCP | LDAPS | directory | |
| 853 | TCP | DNS over TLS | core | |
| 853 | UDP | DNS over QUIC | core | |
| 873 | TCP | rsync | files | Unauthenticated modules leak data |
| 902 | TCP/UDP | VMware ESXi host agent | virtualization | |
| 989-990 | TCP | FTPS (implicit TLS) | files | |
| 993 | TCP | IMAPS | ||
| 995 | TCP | POP3S | ||
| 1080 | TCP | SOCKS proxy | proxy | Open proxies get abused |
| 1194 | UDP | OpenVPN (default) | vpn | |
| 1433 | TCP | Microsoft SQL Server | database | Do not expose |
| 1434 | UDP | SQL Server Browser | database | |
| 1521 | TCP | Oracle Database listener | database | Do not expose |
| 1701 | UDP | L2TP | vpn | |
| 1720 | TCP | H.323 | voip | |
| 1723 | TCP | PPTP VPN | vpn | Broken encryption; do not use |
| 1812 | UDP | RADIUS authentication | vpn | |
| 1813 | UDP | RADIUS accounting | vpn | |
| 1883 | TCP | MQTT | iot | Use 8883 (TLS) |
| 1900 | UDP | SSDP / UPnP discovery | iot | Do not expose (amplification) |
| 2000 | TCP | Cisco SCCP (Skinny) | voip | |
| 2049 | TCP/UDP | NFS | files | Do not expose |
| 2181 | TCP | Apache ZooKeeper | database | |
| 2375 | TCP | Docker API (no TLS) | containers | Exposure gives root on the host |
| 2376 | TCP | Docker API (TLS) | containers | |
| 2379-2380 | TCP | etcd client / peer | containers | Holds cluster secrets |
| 3000 | TCP | Grafana, Node.js dev servers | web | |
| 3128 | TCP | Squid proxy | proxy | |
| 3260 | TCP | iSCSI | storage | Keep on a storage network |
| 3268-3269 | TCP | Active Directory global catalog | directory | |
| 3306 | TCP | MySQL / MariaDB | database | Do not expose |
| 3389 | TCP/UDP | Remote Desktop (RDP) | remote | Frequent ransomware entry point; use a VPN or gateway |
| 3478 | TCP/UDP | STUN / TURN | voip | |
| 4369 | TCP | Erlang port mapper (RabbitMQ) | database | |
| 4500 | UDP | IPsec NAT traversal | vpn | |
| 4789 | UDP | VXLAN | routing | |
| 5000 | TCP | UPnP, Flask dev, Synology DSM | web | |
| 5044 | TCP | Logstash Beats input | monitoring | |
| 5060 | TCP/UDP | SIP | voip | Scanned constantly for toll fraud |
| 5061 | TCP | SIP over TLS | voip | |
| 5201 | TCP | iperf3 | monitoring | |
| 5222 | TCP | XMPP client | other | |
| 5353 | UDP | mDNS (Bonjour) | iot | |
| 5355 | UDP | LLMNR | windows | Disable; used for credential capture |
| 5432 | TCP | PostgreSQL | database | Do not expose |
| 5601 | TCP | Kibana | monitoring | |
| 5672 | TCP | AMQP (RabbitMQ) | database | |
| 5900 | TCP | VNC | remote | Often weakly protected; do not expose |
| 5938 | TCP | TeamViewer | remote | |
| 5985 | TCP | WinRM (HTTP) | windows | Do not expose |
| 5986 | TCP | WinRM (HTTPS) | windows | |
| 6379 | TCP | Redis | database | No authentication by default; do not expose |
| 6443 | TCP | Kubernetes API server | containers | |
| 6514 | TCP | Syslog over TLS | monitoring | |
| 6881-6889 | TCP/UDP | BitTorrent | other | |
| 8000 | TCP | HTTP alternative (dev servers) | web | |
| 8080 | TCP | HTTP alternative, proxies | web | |
| 8086 | TCP | InfluxDB | database | |
| 8291 | TCP | MikroTik Winbox | remote | Do not expose |
| 8443 | TCP | HTTPS alternative | web | |
| 8728 | TCP | MikroTik API | remote | |
| 8729 | TCP | MikroTik API (TLS) | remote | |
| 8883 | TCP | MQTT over TLS | iot | |
| 9000 | TCP | PHP-FPM, various admin panels | web | PHP-FPM must stay local |
| 9090 | TCP | Prometheus | monitoring | |
| 9092 | TCP | Apache Kafka | database | |
| 9100 | TCP | Prometheus node exporter / raw printing (JetDirect) | monitoring | |
| 9200 | TCP | Elasticsearch HTTP | database | Do not expose |
| 9300 | TCP | Elasticsearch transport | database | |
| 10000 | TCP | Webmin | remote | |
| 10050 | TCP | Zabbix agent | monitoring | |
| 10051 | TCP | Zabbix server | monitoring | |
| 10250 | TCP | Kubelet API | containers | Do not expose |
| 11211 | TCP/UDP | Memcached | database | UDP enabled it is a DDoS amplifier |
| 15672 | TCP | RabbitMQ management | database | |
| 20000 | TCP | DNP3 | industrial | Never expose |
| 25565 | TCP | Minecraft | other | |
| 27017 | TCP | MongoDB | database | Do not expose |
| 44818 | TCP/UDP | EtherNet/IP (CIP) | industrial | Never expose |
| 47808 | UDP | BACnet (building automation) | industrial | Never expose |
| 51820 | UDP | WireGuard (common default) | vpn |
- Port numbers only indicate the usual service; any program can listen on any port. Check what is really running with ss -tulpn (Linux), Get-NetTCPConnection (Windows) or netstat.
- The official registry is the IANA Service Name and Transport Protocol Port Number Registry.
So verwenden Sie das Tool: TCP/UDP-Port-Suche
Geben Sie Daten ein oder wählen Sie eine Datei. Passen Sie die Einstellungen an, erstellen Sie das Ergebnis und prüfen Sie es vor dem Kopieren oder Herunterladen.
Grenzen und unterstützte Formate
Ihre Eingaben werden auf Ihrem Gerät verarbeitet.
Technische Hinweise auf Englisch
A curated list of 123 common ports, not the full IANA registry. Any program can listen on any port. Everything is calculated in your browser; nothing is sent or probed on the network.
Ranges such as 6881–6889 match any number inside them; text searches look at the service, category and notes.
3389 is RDP (TCP/UDP): a frequent ransomware entry point that should sit behind a VPN or gateway.