All sheets · Use your browser Print dialog (Ctrl P) and Save as PDF.
Z+
Ports and protocol numbers
Conventional/default values; administrators can change them. ESP 50 and AH 51 are IP protocol numbers, not TCP/UDP ports. Stories are invented memory aids, not historical reasons for the numbers. Registry: https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
| Topic | Remember |
|---|---|
| FTP data — TCP 20 | File Transfer Protocol (active data). Traditional active-mode server data source. The delivery warehouse: desk 21 takes orders; bay 20 sends active deliveries. Note: Passive FTP data uses a negotiated port, not universally 20. |
| FTP — TCP 21 | File Transfer Protocol. Control connection for FTP commands. The delivery warehouse: desk 21 takes orders; bay 20 sends active deliveries. Note: Allowing TCP 21 alone can permit login while blocking transfers. |
| SSH — TCP 22 | Secure Shell. Encrypted remote access; also carries SFTP. Two identical keys at door 22; next door 23 has its window wide open. Note: SFTP rides SSH. It is not FTP with a certificate. |
| Telnet — TCP 23 | Telnet. Unencrypted remote terminal access. Two identical keys at door 22; next door 23 has its window wide open. |
| SMTP — TCP 25 | Simple Mail Transfer Protocol. Server mail relay. Mail truck 25; submission desk 587. Note: Relay commonly TCP 25, which can also negotiate STARTTLS. |
| DNS — TCP/UDP 53 | Domain Name System. Name-to-address resolution. At house 53, a sign translates names into addresses. Say “five-three, names to IP.” Note: TCP is not reserved exclusively for zone transfers. |
| DHCP server — UDP 67 | Dynamic Host Configuration Protocol (server). DHCP server listener. Landlord 67 gives an address to tenant 68. |
| DHCP client — UDP 68 | Dynamic Host Configuration Protocol (client). DHCP client listener. Landlord 67 gives an address to tenant 68. |
| TFTP — UDP 69 | Trivial File Transfer Protocol. Initial TFTP request; later transfer uses negotiated identifiers/ports. Tiny file booth 69. |
| HTTP — TCP 80 | Hypertext Transfer Protocol. Ordinary web pages. Café 80 serves ordinary web pages; vault 443 serves protected web pages. |
| Kerberos — TCP/UDP 88 | Kerberos. Ticket-based authentication. The twin eights at gate 88 look like a pair of entry tickets. |
| POP3 — TCP 110 | Post Office Protocol version 3. Retrieve mail from a mailbox. Post office 110, secure locker 995. |
| NTP — UDP 123 | Network Time Protocol. Time synchronization. At clock 123, count “one-two-three, synchronize me.” |
| SMB over NetBIOS — TCP 139 | Legacy Server Message Block over NetBIOS. Legacy SMB session service. Older hallway 139 before the direct door at 445. Note: Module 7 page 23. Modern direct SMB uses TCP 445. |
| IMAP — TCP 143 | Internet Message Access Protocol. Mailbox access that keeps mail on the server. Mailbox mirror 143, secure mirror 993. |
| SNMP — UDP 161 | Simple Network Management Protocol (queries). Manager queries to an agent. At 161, ask “one question”; at 162, receive “two kinds of notification: traps/informs.” |
| SNMP notifications — UDP 162 | Simple Network Management Protocol (traps/informs). Notification receiver for traps and informs. At 161, ask “one question”; at 162, receive “two kinds of notification: traps/informs.” |
| LDAP — TCP 389 | Lightweight Directory Access Protocol. Directory queries; StartTLS can protect 389. At 389, open a directory; at 636, picture two padlocks shaped like sixes guarding shelf three. Note: Port 389 does not prove plaintext because StartTLS may protect it. |
| HTTPS — TCP 443 | HTTP over TLS. TLS-protected web. Café 80 serves ordinary web pages; vault 443 serves protected web pages. Imagine “four walls, four guards, three locks.” Note: HTTP/3 uses QUIC over UDP, commonly 443. QUIC is the protocol’s name; do not invent a formal expansion. |
| SMB — TCP 445 | Server Message Block. Modern direct file and printer sharing. Room 445 has “four coworkers, four folders, five shared files.” |
| SMTPS — TCP 465 | SMTP implicit TLS submission. Mail submission with implicit TLS. Locked mail desk 465 sits near submission desk 587. Note: Module 7 page 32. Submission commonly TCP 587 with STARTTLS. |
| TACACS+ — TCP 49 | Terminal Access Controller Access-Control System Plus. Device administration AAA. Administrator gate 49. |
| IKE — UDP 500 | Internet Key Exchange. IPsec key/setting negotiation. VPN guard 500 starts negotiation; truck 4500 carries it through the address translator. |
| Syslog — UDP 514 | Syslog. Event record delivery. At 514, the logbook says “five events, one timeline, four clues.” |
| LPD — TCP 515 | Line Printer Daemon. Print queue. Print queue 515 beside logbook 514. |
| IPP — TCP 631 | Internet Printing Protocol. Network printing. Six pages, three copies, one printer. |
| LDAPS — TCP 636 | LDAP over TLS. Directory access with implicit TLS. At 389, open a directory; at 636, picture two padlocks shaped like sixes guarding shelf three. |
| SQL Server — TCP 1433 | Microsoft SQL Server database listener. SQL Server listener. SQL shelf 1433. |
| Oracle SQL*Net — TCP 1521 | Oracle SQL*Net. Oracle database listener. Oracle office 1521. Note: Module 7 page 25. Required exam port from the slides. |
| RADIUS — UDP 1812 | Remote Authentication Dial-In User Service (authentication/authorization). Authentication and authorization. At reception 1812 you prove access; at checkout 1813 they record the visit. |
| RADIUS accounting — UDP 1813 | Remote Authentication Dial-In User Service (accounting). Accounting records. At reception 1812 you prove access; at checkout 1813 they record the visit. |
| NFS — TCP 2049 | Network File System. Network file service. Network filing cabinet 2049. Note: Version/deployment may add transports/services. |
| MySQL — TCP 3306 | MySQL / MariaDB database listener. MySQL/MariaDB listener. My database cabinet 3306. |
| RDP — TCP/UDP 3389 | Remote Desktop Protocol. Remote graphical desktop. Two threes sit at desk 89. |
| NAT-T — UDP 4500 | IPsec NAT Traversal. Carry IPsec through network address translation. VPN guard 500 starts negotiation; truck 4500 carries it through the address translator. |
| SIP — TCP/UDP 5060 | Session Initiation Protocol. Call setup signaling. At doors 5060 and 5061: “sixty says hello; sixty-one locks the call setup.” Note: Media ports are separate negotiated RTP ports. |
| SIP/TLS — TCP 5061 | SIP over TLS. TLS-protected call setup. At doors 5060 and 5061: “sixty says hello; sixty-one locks the call setup.” |
| PostgreSQL — TCP 5432 | PostgreSQL database listener. PostgreSQL listener. Database countdown five-four-three-two. |
| SMTP submission — TCP 587 | Mail submission (commonly STARTTLS). Client mail submission. Mail truck 25; submission desk 587. |
| Syslog TLS — TCP 6514 | TLS-protected Syslog. Encrypted syslog delivery. Put security in front of logbook 514: 6514. |
| IMAPS — TCP 993 | IMAP implicit TLS. Mailbox access with implicit TLS. Mailbox mirror 143, secure mirror 993. |
| POP3S — TCP 995 | POP3 implicit TLS. Mail retrieval with implicit TLS. Post office 110, secure locker 995. |
| FTPS implicit — TCP 990 | FTP over TLS (implicit). Implicit FTPS control. Locked warehouse 990 still uses FTP-style control and data. Note: Module 7 page 22. Explicit FTPS commonly begins on TCP 21. SFTP is not FTPS. |
| AppSocket — TCP 9100 | Raw printer / AppSocket service. Raw print stream. Big printer at bay 9100. |
| ESP — IP 50 (protocol ID) | Encapsulating Security Payload. IPsec payload protection (protocol number, not a TCP/UDP port). ESP is protocol 50 on the IP layer — not door 50. Note: Never grade ESP 50 as a TCP/UDP port answer. |
| AH — IP 51 (protocol ID) | Authentication Header. IPsec integrity/authentication (protocol number, not a TCP/UDP port). AH is protocol 51 on the IP layer — not door 51. Note: AH does not encrypt. Never grade AH 51 as a TCP/UDP port answer. |