Port and protocol guide
Which service uses which port, is it encrypted, should it face the internet? Search by port number or service name and filter by category, with industrial and OT protocols (Modbus, S7comm, OPC UA, EtherNet/IP, BACnet) included. You can copy the table as CSV.
Type a port number, service name or description; you can also enter a range such as 8000-8100.
99 of 99 entries
| Port | Protocol | Service and security note | Encrypted | Internet exposure |
|---|---|---|---|---|
| 80 | TCP | HTTP · Web · IANA registry Unencrypted web traffic (HTTP) May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS. | No | Only if protected |
| 443 | TCP/UDP | HTTPS · Web · IANA registry Web over TLS (HTTPS); HTTP/3 (QUIC) over UDP May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS. | Yes | Only if protected |
| 8080 | TCP | HTTP-Alt · Web · IANA registry Alternative HTTP; proxies and application servers May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS. | No | Only if protected |
| 8443 | TCP | HTTPS-Alt · Web · Application default Alternative HTTPS; admin consoles and application servers May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS. | Optional | Only if protected |
| 25 | TCP | SMTP · Email · IANA registry Mail transfer between servers (MTA) Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay. | Optional | Only if protected |
| 110 | TCP | POP3 · Email · IANA registry Mail retrieval from the server (unencrypted) Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Only if protected |
| 143 | TCP | IMAP · Email · IANA registry Mailbox access on the server (can be encrypted with STARTTLS) Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | Optional | Only if protected |
| 465 | TCP | SMTPS (submissions) · Email · IANA registry Client mail submission over TLS Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay. | Yes | Only if protected |
| 587 | TCP | SMTP submission · Email · IANA registry Authenticated client mail submission (STARTTLS) Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay. | Optional | Only if protected |
| 993 | TCP | IMAPS · Email · IANA registry IMAP over TLS Encrypted channel: keep certificates and the TLS version up to date. | Yes | Only if protected |
| 995 | TCP | POP3S · Email · IANA registry POP3 over TLS Encrypted channel: keep certificates and the TLS version up to date. | Yes | Only if protected |
| 88 | TCP/UDP | Kerberos · Directory / Identity · IANA registry Kerberos authentication (including Active Directory) Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Optional | Do not expose directly to the internet |
| 389 | TCP/UDP | LDAP · Directory / Identity · IANA registry Directory queries (including Active Directory) Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Optional | Do not expose directly to the internet |
| 464 | TCP/UDP | kpasswd · Directory / Identity · IANA registry Kerberos password change Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Optional | Do not expose directly to the internet |
| 636 | TCP | LDAPS · Directory / Identity · IANA registry LDAP over TLS Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Yes | Do not expose directly to the internet |
| 3268 | TCP | Global Catalog · Directory / Identity · IANA registry Active Directory global catalog (LDAP) Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Optional | Do not expose directly to the internet |
| 3269 | TCP | Global Catalog SSL · Directory / Identity · IANA registry Active Directory global catalog (LDAPS) Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing. | Yes | Do not expose directly to the internet |
| 1812 | UDP | RADIUS · Directory / Identity · IANA registry RADIUS authentication (Wi-Fi, VPN, 802.1X) AAA service: allow access only from network devices; use a strong shared secret. | Optional | Do not expose directly to the internet |
| 1813 | UDP | RADIUS accounting · Directory / Identity · IANA registry RADIUS accounting AAA service: allow access only from network devices; use a strong shared secret. | Optional | Do not expose directly to the internet |
| 49 | TCP | TACACS+ · Directory / Identity · IANA registry Authentication and authorization for network device administration AAA service: allow access only from network devices; use a strong shared secret. | Optional | Do not expose directly to the internet |
| 1433 | TCP | Microsoft SQL Server · Database · IANA registry Microsoft SQL Server database engine Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 1434 | UDP | SQL Server Browser · Database · IANA registry SQL Server named-instance resolution Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | No | Do not expose directly to the internet |
| 1521 | TCP | Oracle Listener · Database · Application default Oracle database listener (default) Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 3306 | TCP | MySQL / MariaDB · Database · IANA registry MySQL and MariaDB database Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 5432 | TCP | PostgreSQL · Database · IANA registry PostgreSQL database Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 6379 | TCP | Redis · Database · Application default Redis in-memory key-value store A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS. | Optional | Do not expose directly to the internet |
| 9200 | TCP | Elasticsearch · Database · Application default Elasticsearch REST API (HTTP) A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS. | Optional | Do not expose directly to the internet |
| 9042 | TCP | Cassandra CQL · Database · Application default Apache Cassandra client connection (CQL) Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 11211 | TCP/UDP | Memcached · Database · IANA registry Memcached cache A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS. | No | Do not expose directly to the internet |
| 27017 | TCP | MongoDB · Database · Application default MongoDB database (default) Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 8086 | TCP | InfluxDB · Database · Application default InfluxDB HTTP API (time series) Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network. | Optional | Do not expose directly to the internet |
| 22 | TCP | SSH · Remote access and VPN · IANA registry Secure shell; SFTP and SCP also run over it A constant target of password guessing: use key-based authentication or MFA, IP restriction and rate limiting. | Yes | Only if protected |
| 23 | TCP | Telnet · Remote access and VPN · IANA registry Unencrypted remote shell (legacy) An old, weak protocol: use a modern, authenticated and encrypted alternative instead. | No | Do not expose directly to the internet |
| 3389 | TCP/UDP | RDP · Remote access and VPN · IANA registry Windows Remote Desktop A frequent entry point for ransomware attacks: do not expose directly to the internet; keep it behind a VPN or a remote desktop gateway and MFA. | Yes | Do not expose directly to the internet |
| 5900 | TCP | VNC (RFB) · Remote access and VPN · IANA registry VNC remote desktop; unencrypted without extra configuration Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 5985 | TCP | WinRM (HTTP) · Remote access and VPN · IANA registry Windows Remote Management (WinRM), HTTP Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 5986 | TCP | WinRM (HTTPS) · Remote access and VPN · IANA registry Windows Remote Management (WinRM), HTTPS Management interface: make it reachable only from the management network; do not expose to the internet. | Yes | Do not expose directly to the internet |
| 1194 | TCP/UDP | OpenVPN · Remote access and VPN · IANA registry OpenVPN tunnel (mostly UDP) A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA. | Yes | Only if protected |
| 51820 | UDP | WireGuard · Remote access and VPN · Application default WireGuard VPN (common default listen port) A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA. | Yes | Only if protected |
| 500 | UDP | IKE (ISAKMP) · Remote access and VPN · IANA registry IPsec key exchange (IKE) A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA. | Yes | Only if protected |
| 4500 | UDP | IPsec NAT-T · Remote access and VPN · IANA registry IPsec NAT traversal (NAT-T) A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA. | Yes | Only if protected |
| 1701 | UDP | L2TP · Remote access and VPN · IANA registry L2TP tunnelling (usually together with IPsec) A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA. | No | Only if protected |
| 1723 | TCP | PPTP · Remote access and VPN · IANA registry PPTP VPN control connection (legacy) An old, weak protocol: use a modern, authenticated and encrypted alternative instead. | Optional | Only if protected |
| 102 | TCP | S7comm (ISO-on-TCP) · Industrial / OT · IANA registry Siemens S7 communication (ISO-on-TCP) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 502 | TCP | Modbus TCP · Industrial / OT · IANA registry Modbus TCP (MBAP) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 1911 | TCP | Niagara Fox · Industrial / OT · IANA registry Niagara Fox (building automation) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 4911 | TCP | Niagara Foxs · Industrial / OT · Application default Niagara Fox over TLS (default) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | Yes | Do not expose directly to the internet |
| 2222 | UDP | EtherNet/IP (implicit) · Industrial / OT · IANA registry EtherNet/IP implicit I/O messaging Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 44818 | TCP/UDP | EtherNet/IP (explicit) · Industrial / OT · IANA registry EtherNet/IP explicit messaging (CIP) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 2404 | TCP | IEC 60870-5-104 · Industrial / OT · IANA registry IEC 60870-5-104 (power and SCADA telecontrol) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 4840 | TCP | OPC UA · Industrial / OT · IANA registry OPC UA binary protocol (opc.tcp); security mode is configurable Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | Optional | Do not expose directly to the internet |
| 5094 | TCP/UDP | HART-IP · Industrial / OT · IANA registry HART-IP (field device communication) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 20000 | TCP/UDP | DNP3 · Industrial / OT · IANA registry DNP3 (power and water SCADA) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 34962 | TCP/UDP | PROFINET RT · Industrial / OT · IANA registry PROFINET real-time I/O Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 34963 | TCP/UDP | PROFINET RTM · Industrial / OT · IANA registry PROFINET (profinet-rtm registration) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 34964 | TCP/UDP | PROFINET CM · Industrial / OT · IANA registry PROFINET context management Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 47808 | UDP | BACnet/IP · Industrial / OT · IANA registry BACnet/IP (building automation) Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ). | No | Do not expose directly to the internet |
| 1883 | TCP | MQTT · Messaging · IANA registry MQTT, unencrypted Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 8883 | TCP | MQTT over TLS · Messaging · IANA registry MQTT over TLS Encrypted channel: keep certificates and the TLS version up to date. | Yes | Only if protected |
| 5671 | TCP | AMQPS · Messaging · IANA registry AMQP over TLS Message broker: enable authentication and TLS; allow access from the internal network only. | Yes | Do not expose directly to the internet |
| 5672 | TCP | AMQP · Messaging · IANA registry AMQP (RabbitMQ default) Message broker: enable authentication and TLS; allow access from the internal network only. | Optional | Do not expose directly to the internet |
| 9092 | TCP | Kafka · Messaging · Application default Apache Kafka broker (default) Message broker: enable authentication and TLS; allow access from the internal network only. | Optional | Do not expose directly to the internet |
| 2181 | TCP | ZooKeeper · Messaging · Application default Apache ZooKeeper client connection (default) Message broker: enable authentication and TLS; allow access from the internal network only. | Optional | Do not expose directly to the internet |
| 4222 | TCP | NATS · Messaging · Application default NATS client connection (default) Message broker: enable authentication and TLS; allow access from the internal network only. | Optional | Do not expose directly to the internet |
| 5060 | TCP/UDP | SIP · Messaging · IANA registry SIP signalling (VoIP), unencrypted A target of brute force and toll fraud: use authentication, rate limiting and a session border controller (SBC). | No | Only if protected |
| 5061 | TCP | SIP over TLS · Messaging · IANA registry SIP signalling over TLS A target of brute force and toll fraud: use authentication, rate limiting and a session border controller (SBC). | Yes | Only if protected |
| 5222 | TCP | XMPP · Messaging · IANA registry XMPP client connection (instant messaging) A constant target of password guessing: use key-based authentication or MFA, IP restriction and rate limiting. | Optional | Only if protected |
| 53 | TCP/UDP | DNS · Network management · IANA registry Name resolution; large answers and zone transfers use TCP May be public for an authoritative server; restrict recursion and apply response rate limiting. | No | Only if protected |
| 67 | UDP | DHCP sunucu (BOOTP) · Network management · IANA registry DHCP server side Local network protocol: do not expose to the internet; block at the perimeter firewall. | No | Do not expose directly to the internet |
| 68 | UDP | DHCP istemci · Network management · IANA registry DHCP client side Local network protocol: do not expose to the internet; block at the perimeter firewall. | No | Do not expose directly to the internet |
| 69 | UDP | TFTP · Network management · IANA registry Simple file transfer without authentication (device firmware, PXE) An old, weak protocol: use a modern, authenticated and encrypted alternative instead. | No | Do not expose directly to the internet |
| 123 | UDP | NTP · Network management · IANA registry Network time synchronisation (NTP) Can be abused in UDP reflection/amplification attacks; open it only to the sources that need it. | No | Only if protected |
| 161 | UDP | SNMP · Network management · IANA registry SNMP queries (v3 offers authentication and encryption) Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 162 | UDP | SNMP trap · Network management · IANA registry SNMP trap and inform notifications Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 179 | TCP | BGP · Network management · IANA registry Border Gateway Protocol (BGP) Routing protocol: run it only with known peers, with authentication and ACLs; apply prefix filters. | No | Do not expose directly to the internet |
| 514 | UDP | Syslog · Network management · IANA registry Syslog log forwarding (UDP) Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 137 | UDP | NetBIOS-NS · Network management · IANA registry NetBIOS name service A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1. | No | Do not expose directly to the internet |
| 138 | UDP | NetBIOS-DGM · Network management · IANA registry NetBIOS datagram service A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1. | No | Do not expose directly to the internet |
| 135 | TCP | MSRPC · Network management · IANA registry Windows RPC endpoint mapper A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1. | No | Do not expose directly to the internet |
| 520 | UDP | RIP · Network management · IANA registry RIP routing Routing protocol: run it only with known peers, with authentication and ACLs; apply prefix filters. | No | Do not expose directly to the internet |
| 5353 | UDP | mDNS · Network management · IANA registry Multicast DNS on the local network (mDNS) Local network protocol: do not expose to the internet; block at the perimeter firewall. | No | Do not expose directly to the internet |
| 2375 | TCP | Docker API · Network management · IANA registry Docker Engine API, unencrypted A management API gives full control: never expose it to the internet without authentication or encryption. | No | Do not expose directly to the internet |
| 2376 | TCP | Docker API (TLS) · Network management · IANA registry Docker Engine API over TLS A management API gives full control: never expose it to the internet without authentication or encryption. | Yes | Do not expose directly to the internet |
| 6443 | TCP | Kubernetes API · Network management · Application default Kubernetes API server (default) A management API gives full control: never expose it to the internet without authentication or encryption. | Yes | Do not expose directly to the internet |
| 2379 | TCP | etcd · Network management · IANA registry etcd client connection A management API gives full control: never expose it to the internet without authentication or encryption. | Optional | Do not expose directly to the internet |
| 9090 | TCP | Prometheus · Network management · Application default Prometheus monitoring server (default) Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 5601 | TCP | Kibana · Network management · Application default Kibana interface (default) Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 10050 | TCP | Zabbix agent · Network management · IANA registry Zabbix agent Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 10051 | TCP | Zabbix trapper · Network management · IANA registry Zabbix server / trapper Management interface: make it reachable only from the management network; do not expose to the internet. | Optional | Do not expose directly to the internet |
| 20 | TCP | FTP data · File transfer · IANA registry FTP data connection (active mode) Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 21 | TCP | FTP · File transfer · IANA registry FTP control connection Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 989 | TCP | FTPS data · File transfer · IANA registry FTP data connection over TLS (implicit) Encrypted channel: keep certificates and the TLS version up to date. | Yes | Only if protected |
| 990 | TCP | FTPS · File transfer · IANA registry FTP control connection over TLS (implicit) Encrypted channel: keep certificates and the TLS version up to date. | Yes | Only if protected |
| 111 | TCP/UDP | RPC portmapper · File transfer · IANA registry Sun RPC portmapper (used by NFS) Local network protocol: do not expose to the internet; block at the perimeter firewall. | No | Do not expose directly to the internet |
| 139 | TCP | NetBIOS-SSN · File transfer · IANA registry NetBIOS session service (legacy SMB) A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1. | No | Do not expose directly to the internet |
| 445 | TCP | SMB · File transfer · IANA registry SMB/CIFS file and printer sharing A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1. | Optional | Do not expose directly to the internet |
| 2049 | TCP/UDP | NFS · File transfer · IANA registry Network File System (NFS) NFS: expose only to a trusted network; restrict clients and consider Kerberos-based security. | Optional | Do not expose directly to the internet |
| 873 | TCP | rsync · File transfer · IANA registry rsync file synchronisation (daemon mode) Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS). | No | Do not expose directly to the internet |
| 3260 | TCP | iSCSI · File transfer · IANA registry iSCSI storage target Storage network: keep it on a separate network; use CHAP and IP restrictions. | No | Do not expose directly to the internet |
Verify against the IANA service name and port number registry and the application documentation.
Port ranges
- Well-known ports (0–1023)
- System ports: basic services assigned by IANA (HTTP, SSH, SMTP...). On most operating systems listening on them needs privileges.
- Registered ports (1024–49151)
- Ports applications have registered with IANA (databases, protocols). Many products' defaults are here.
- Dynamic / private ports (49152–65535)
- The unassigned range: for clients' ephemeral source ports and private use. Some operating systems use a different ephemeral range.
Data and assumptions
- Source: the "IANA registry" label marks a known assignment in the IANA service name and port number registry; "Application default" marks a product's common default port, for which the IANA entry may differ.
- The protocol column shows the port's typical use; some ports are registered for both TCP and UDP or vary by application.
- "Encrypted": Yes = the channel is encrypted by default, No = unencrypted, Optional = depends on version or configuration (STARTTLS, TLS setting).
- "Do not expose directly to the internet" is a general principle, not a firm verdict for every environment; always weigh access against need, authentication and network segmentation.
Search and filters run in your browser; what you type is not sent to a server and not stored.
This guide is for general information, is not exhaustive and does not replace product-specific configuration: before opening or closing a port, verify it against the IANA registry and the documentation of the application concerned. The security notes are general good practice; they give no audit or compliance assurance.
Shall we review your firewall rules, network segmentation and OT/IT boundary together?
Request a meeting01
How to use
A
Type a port number, a service name or a range (e.g. 8000-8100) in the search box.
B
Filter by category and protocol; if you like, show only those that should not face the internet directly.
C
Read the encryption and internet-exposure warning on each row; copy the visible table as CSV and verify the rules against your own documentation.
02
What a port is and what the ranges mean
A port is a 16-bit number (0–65535) that tells apart the services on one IP address. TCP and UDP ports are separate: the same number can belong to different services in the two protocols. IANA groups the numbers into three ranges: well-known (0–1023), registered (1024–49151) and dynamic/private (49152–65535).
A port being registered with IANA does not mean the service will only use that port; administrators can move a service to another port and products can choose different defaults. That is why the table states the source (IANA registry or application default) separately.
03
Why the "do not expose directly to the internet" warning
Databases, remote desktop (RDP), file sharing (SMB), management APIs and industrial/OT protocols become frequent attack targets when opened to remote, unauthenticated sources. Many OT protocols such as Modbus, S7comm, DNP3, EtherNet/IP and BACnet have no authentication or encryption by design; anyone who can reach an internet-facing PLC can read or write it.
In practice it is advisable to keep access behind a VPN, a remote access gateway or a DMZ, to segment the network into IT and OT, and to allow only the source addresses that need access. The warning in the table is a starting point; assess the rules for your own environment.
04
Encrypted and unencrypted protocols
Old protocols such as HTTP, FTP, Telnet, POP3 and SNMPv1/v2c send data and passwords in the clear; anyone listening on the network can read them. Most have a TLS-protected counterpart (HTTPS, FTPS/SFTP, SSH, POP3S/IMAPS, SNMPv3). Rows marked "Optional" depend on version or configuration (e.g. STARTTLS); do not assume encryption is on, check your configuration.
Being encrypted does not make exposing a service to the internet safe: authentication, patch status and access restrictions remain decisive.
FAQ
- Is my search sent anywhere?
- No. Search and filters run in your browser; what you type is not sent to a server and is not stored.
- Is the table complete?
- No. It contains a selection of common services and industrial/OT protocols whose source is certain. For a port not on the list, check the IANA registry and the product documentation.
- What is the difference between "IANA registry" and "Application default"?
- An IANA registry entry is the official assignment of a service name and port number. An application default is the common port a product uses on installation; IANA may have assigned it to another service, and it can be changed in the settings.
- Which OT protocols are unencrypted?
- Modbus TCP, classic S7comm, DNP3, IEC 60870-5-104, EtherNet/IP, BACnet/IP and classic PROFINET offer no authentication or encryption. OPC UA has security modes but they must be configured; secure variants of some protocols are defined in separate specifications.
- What should I do if I must expose a port to the internet?
- First consider an alternative (VPN, remote access gateway, reverse proxy). If it is still necessary, restrict the source IP, use strong authentication and TLS, keep the software up to date, and log and monitor access.
- What is the dynamic port range used for?
- The 49152–65535 range is unassigned: it is used for clients' ephemeral source ports and private use. Some systems define different ephemeral ranges; check your own operating system's setting.
Do your firewall and network segmentation need a review?
Let us do the design and rule review together for corporate networks, OT/SCADA segmentation, remote access and cloud connections. In a free discovery call we discuss your current state.