Z+

All sheets · Use your browser Print dialog (Ctrl P) and Save as PDF.

Z+

Ports and protocol numbers

Conventional/default values; administrators can change them. ESP 50 and AH 51 are IP protocol numbers, not TCP/UDP ports. Stories are invented memory aids, not historical reasons for the numbers. Registry: https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

TopicRemember
FTP data — TCP 20File Transfer Protocol (active data). Traditional active-mode server data source. The delivery warehouse: desk 21 takes orders; bay 20 sends active deliveries. Note: Passive FTP data uses a negotiated port, not universally 20.
FTP — TCP 21File Transfer Protocol. Control connection for FTP commands. The delivery warehouse: desk 21 takes orders; bay 20 sends active deliveries. Note: Allowing TCP 21 alone can permit login while blocking transfers.
SSH — TCP 22Secure Shell. Encrypted remote access; also carries SFTP. Two identical keys at door 22; next door 23 has its window wide open. Note: SFTP rides SSH. It is not FTP with a certificate.
Telnet — TCP 23Telnet. Unencrypted remote terminal access. Two identical keys at door 22; next door 23 has its window wide open.
SMTP — TCP 25Simple Mail Transfer Protocol. Server mail relay. Mail truck 25; submission desk 587. Note: Relay commonly TCP 25, which can also negotiate STARTTLS.
DNS — TCP/UDP 53Domain Name System. Name-to-address resolution. At house 53, a sign translates names into addresses. Say “five-three, names to IP.” Note: TCP is not reserved exclusively for zone transfers.
DHCP server — UDP 67Dynamic Host Configuration Protocol (server). DHCP server listener. Landlord 67 gives an address to tenant 68.
DHCP client — UDP 68Dynamic Host Configuration Protocol (client). DHCP client listener. Landlord 67 gives an address to tenant 68.
TFTP — UDP 69Trivial File Transfer Protocol. Initial TFTP request; later transfer uses negotiated identifiers/ports. Tiny file booth 69.
HTTP — TCP 80Hypertext Transfer Protocol. Ordinary web pages. Café 80 serves ordinary web pages; vault 443 serves protected web pages.
Kerberos — TCP/UDP 88Kerberos. Ticket-based authentication. The twin eights at gate 88 look like a pair of entry tickets.
POP3 — TCP 110Post Office Protocol version 3. Retrieve mail from a mailbox. Post office 110, secure locker 995.
NTP — UDP 123Network Time Protocol. Time synchronization. At clock 123, count “one-two-three, synchronize me.”
SMB over NetBIOS — TCP 139Legacy Server Message Block over NetBIOS. Legacy SMB session service. Older hallway 139 before the direct door at 445. Note: Module 7 page 23. Modern direct SMB uses TCP 445.
IMAP — TCP 143Internet Message Access Protocol. Mailbox access that keeps mail on the server. Mailbox mirror 143, secure mirror 993.
SNMP — UDP 161Simple Network Management Protocol (queries). Manager queries to an agent. At 161, ask “one question”; at 162, receive “two kinds of notification: traps/informs.”
SNMP notifications — UDP 162Simple Network Management Protocol (traps/informs). Notification receiver for traps and informs. At 161, ask “one question”; at 162, receive “two kinds of notification: traps/informs.”
LDAP — TCP 389Lightweight Directory Access Protocol. Directory queries; StartTLS can protect 389. At 389, open a directory; at 636, picture two padlocks shaped like sixes guarding shelf three. Note: Port 389 does not prove plaintext because StartTLS may protect it.
HTTPS — TCP 443HTTP over TLS. TLS-protected web. Café 80 serves ordinary web pages; vault 443 serves protected web pages. Imagine “four walls, four guards, three locks.” Note: HTTP/3 uses QUIC over UDP, commonly 443. QUIC is the protocol’s name; do not invent a formal expansion.
SMB — TCP 445Server Message Block. Modern direct file and printer sharing. Room 445 has “four coworkers, four folders, five shared files.”
SMTPS — TCP 465SMTP implicit TLS submission. Mail submission with implicit TLS. Locked mail desk 465 sits near submission desk 587. Note: Module 7 page 32. Submission commonly TCP 587 with STARTTLS.
TACACS+ — TCP 49Terminal Access Controller Access-Control System Plus. Device administration AAA. Administrator gate 49.
IKE — UDP 500Internet Key Exchange. IPsec key/setting negotiation. VPN guard 500 starts negotiation; truck 4500 carries it through the address translator.
Syslog — UDP 514Syslog. Event record delivery. At 514, the logbook says “five events, one timeline, four clues.”
LPD — TCP 515Line Printer Daemon. Print queue. Print queue 515 beside logbook 514.
IPP — TCP 631Internet Printing Protocol. Network printing. Six pages, three copies, one printer.
LDAPS — TCP 636LDAP over TLS. Directory access with implicit TLS. At 389, open a directory; at 636, picture two padlocks shaped like sixes guarding shelf three.
SQL Server — TCP 1433Microsoft SQL Server database listener. SQL Server listener. SQL shelf 1433.
Oracle SQL*Net — TCP 1521Oracle SQL*Net. Oracle database listener. Oracle office 1521. Note: Module 7 page 25. Required exam port from the slides.
RADIUS — UDP 1812Remote Authentication Dial-In User Service (authentication/authorization). Authentication and authorization. At reception 1812 you prove access; at checkout 1813 they record the visit.
RADIUS accounting — UDP 1813Remote Authentication Dial-In User Service (accounting). Accounting records. At reception 1812 you prove access; at checkout 1813 they record the visit.
NFS — TCP 2049Network File System. Network file service. Network filing cabinet 2049. Note: Version/deployment may add transports/services.
MySQL — TCP 3306MySQL / MariaDB database listener. MySQL/MariaDB listener. My database cabinet 3306.
RDP — TCP/UDP 3389Remote Desktop Protocol. Remote graphical desktop. Two threes sit at desk 89.
NAT-T — UDP 4500IPsec NAT Traversal. Carry IPsec through network address translation. VPN guard 500 starts negotiation; truck 4500 carries it through the address translator.
SIP — TCP/UDP 5060Session Initiation Protocol. Call setup signaling. At doors 5060 and 5061: “sixty says hello; sixty-one locks the call setup.” Note: Media ports are separate negotiated RTP ports.
SIP/TLS — TCP 5061SIP over TLS. TLS-protected call setup. At doors 5060 and 5061: “sixty says hello; sixty-one locks the call setup.”
PostgreSQL — TCP 5432PostgreSQL database listener. PostgreSQL listener. Database countdown five-four-three-two.
SMTP submission — TCP 587Mail submission (commonly STARTTLS). Client mail submission. Mail truck 25; submission desk 587.
Syslog TLS — TCP 6514TLS-protected Syslog. Encrypted syslog delivery. Put security in front of logbook 514: 6514.
IMAPS — TCP 993IMAP implicit TLS. Mailbox access with implicit TLS. Mailbox mirror 143, secure mirror 993.
POP3S — TCP 995POP3 implicit TLS. Mail retrieval with implicit TLS. Post office 110, secure locker 995.
FTPS implicit — TCP 990FTP over TLS (implicit). Implicit FTPS control. Locked warehouse 990 still uses FTP-style control and data. Note: Module 7 page 22. Explicit FTPS commonly begins on TCP 21. SFTP is not FTPS.
AppSocket — TCP 9100Raw printer / AppSocket service. Raw print stream. Big printer at bay 9100.
ESP — IP 50 (protocol ID)Encapsulating Security Payload. IPsec payload protection (protocol number, not a TCP/UDP port). ESP is protocol 50 on the IP layer — not door 50. Note: Never grade ESP 50 as a TCP/UDP port answer.
AH — IP 51 (protocol ID)Authentication Header. IPsec integrity/authentication (protocol number, not a TCP/UDP port). AH is protocol 51 on the IP layer — not door 51. Note: AH does not encrypt. Never grade AH 51 as a TCP/UDP port answer.

Search

Lessons, ports, glossary