Skip to content

Port and protocol guide

Which service uses which port, is it encrypted, should it face the internet? Search by port number or service name and filter by category, with industrial and OT protocols (Modbus, S7comm, OPC UA, EtherNet/IP, BACnet) included. You can copy the table as CSV.

Free tool · Infrastructure

Type a port number, service name or description; you can also enter a range such as 8000-8100.

99 of 99 entries

PortProtocolService and security noteEncryptedInternet exposure
80TCP

HTTP · Web · IANA registry

Unencrypted web traffic (HTTP)

May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS.

NoOnly if protected
443TCP/UDP

HTTPS · Web · IANA registry

Web over TLS (HTTPS); HTTP/3 (QUIC) over UDP

May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS.

YesOnly if protected
8080TCP

HTTP-Alt · Web · IANA registry

Alternative HTTP; proxies and application servers

May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS.

NoOnly if protected
8443TCP

HTTPS-Alt · Web · Application default

Alternative HTTPS; admin consoles and application servers

May be public: keep software up to date, use a reverse proxy/WAF and redirect HTTP to HTTPS.

OptionalOnly if protected
25TCP

SMTP · Email · IANA registry

Mail transfer between servers (MTA)

Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay.

OptionalOnly if protected
110TCP

POP3 · Email · IANA registry

Mail retrieval from the server (unencrypted)

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoOnly if protected
143TCP

IMAP · Email · IANA registry

Mailbox access on the server (can be encrypted with STARTTLS)

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

OptionalOnly if protected
465TCP

SMTPS (submissions) · Email · IANA registry

Client mail submission over TLS

Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay.

YesOnly if protected
587TCP

SMTP submission · Email · IANA registry

Authenticated client mail submission (STARTTLS)

Mail server: apply authentication, SPF/DKIM/DMARC and check for open relay.

OptionalOnly if protected
993TCP

IMAPS · Email · IANA registry

IMAP over TLS

Encrypted channel: keep certificates and the TLS version up to date.

YesOnly if protected
995TCP

POP3S · Email · IANA registry

POP3 over TLS

Encrypted channel: keep certificates and the TLS version up to date.

YesOnly if protected
88TCP/UDP

Kerberos · Directory / Identity · IANA registry

Kerberos authentication (including Active Directory)

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

OptionalDo not expose directly to the internet
389TCP/UDP

LDAP · Directory / Identity · IANA registry

Directory queries (including Active Directory)

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

OptionalDo not expose directly to the internet
464TCP/UDP

kpasswd · Directory / Identity · IANA registry

Kerberos password change

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

OptionalDo not expose directly to the internet
636TCP

LDAPS · Directory / Identity · IANA registry

LDAP over TLS

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

YesDo not expose directly to the internet
3268TCP

Global Catalog · Directory / Identity · IANA registry

Active Directory global catalog (LDAP)

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

OptionalDo not expose directly to the internet
3269TCP

Global Catalog SSL · Directory / Identity · IANA registry

Active Directory global catalog (LDAPS)

Directory/identity service: do not expose to the internet; enforce encrypted channels (LDAPS/StartTLS) and signing.

YesDo not expose directly to the internet
1812UDP

RADIUS · Directory / Identity · IANA registry

RADIUS authentication (Wi-Fi, VPN, 802.1X)

AAA service: allow access only from network devices; use a strong shared secret.

OptionalDo not expose directly to the internet
1813UDP

RADIUS accounting · Directory / Identity · IANA registry

RADIUS accounting

AAA service: allow access only from network devices; use a strong shared secret.

OptionalDo not expose directly to the internet
49TCP

TACACS+ · Directory / Identity · IANA registry

Authentication and authorization for network device administration

AAA service: allow access only from network devices; use a strong shared secret.

OptionalDo not expose directly to the internet
1433TCP

Microsoft SQL Server · Database · IANA registry

Microsoft SQL Server database engine

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
1434UDP

SQL Server Browser · Database · IANA registry

SQL Server named-instance resolution

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

NoDo not expose directly to the internet
1521TCP

Oracle Listener · Database · Application default

Oracle database listener (default)

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
3306TCP

MySQL / MariaDB · Database · IANA registry

MySQL and MariaDB database

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
5432TCP

PostgreSQL · Database · IANA registry

PostgreSQL database

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
6379TCP

Redis · Database · Application default

Redis in-memory key-value store

A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS.

OptionalDo not expose directly to the internet
9200TCP

Elasticsearch · Database · Application default

Elasticsearch REST API (HTTP)

A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS.

OptionalDo not expose directly to the internet
9042TCP

Cassandra CQL · Database · Application default

Apache Cassandra client connection (CQL)

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
11211TCP/UDP

Memcached · Database · IANA registry

Memcached cache

A default install may have no authentication: bind to the internal interface only; add a password/ACL and TLS.

NoDo not expose directly to the internet
27017TCP

MongoDB · Database · Application default

MongoDB database (default)

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
8086TCP

InfluxDB · Database · Application default

InfluxDB HTTP API (time series)

Database port: do not expose directly to the internet; allow only application servers, a VPN or a private network.

OptionalDo not expose directly to the internet
22TCP

SSH · Remote access and VPN · IANA registry

Secure shell; SFTP and SCP also run over it

A constant target of password guessing: use key-based authentication or MFA, IP restriction and rate limiting.

YesOnly if protected
23TCP

Telnet · Remote access and VPN · IANA registry

Unencrypted remote shell (legacy)

An old, weak protocol: use a modern, authenticated and encrypted alternative instead.

NoDo not expose directly to the internet
3389TCP/UDP

RDP · Remote access and VPN · IANA registry

Windows Remote Desktop

A frequent entry point for ransomware attacks: do not expose directly to the internet; keep it behind a VPN or a remote desktop gateway and MFA.

YesDo not expose directly to the internet
5900TCP

VNC (RFB) · Remote access and VPN · IANA registry

VNC remote desktop; unencrypted without extra configuration

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
5985TCP

WinRM (HTTP) · Remote access and VPN · IANA registry

Windows Remote Management (WinRM), HTTP

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
5986TCP

WinRM (HTTPS) · Remote access and VPN · IANA registry

Windows Remote Management (WinRM), HTTPS

Management interface: make it reachable only from the management network; do not expose to the internet.

YesDo not expose directly to the internet
1194TCP/UDP

OpenVPN · Remote access and VPN · IANA registry

OpenVPN tunnel (mostly UDP)

A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA.

YesOnly if protected
51820UDP

WireGuard · Remote access and VPN · Application default

WireGuard VPN (common default listen port)

A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA.

YesOnly if protected
500UDP

IKE (ISAKMP) · Remote access and VPN · IANA registry

IPsec key exchange (IKE)

A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA.

YesOnly if protected
4500UDP

IPsec NAT-T · Remote access and VPN · IANA registry

IPsec NAT traversal (NAT-T)

A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA.

YesOnly if protected
1701UDP

L2TP · Remote access and VPN · IANA registry

L2TP tunnelling (usually together with IPsec)

A VPN endpoint may face the internet; keep patches current and use strong authentication and MFA.

NoOnly if protected
1723TCP

PPTP · Remote access and VPN · IANA registry

PPTP VPN control connection (legacy)

An old, weak protocol: use a modern, authenticated and encrypted alternative instead.

OptionalOnly if protected
102TCP

S7comm (ISO-on-TCP) · Industrial / OT · IANA registry

Siemens S7 communication (ISO-on-TCP)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
502TCP

Modbus TCP · Industrial / OT · IANA registry

Modbus TCP (MBAP)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
1911TCP

Niagara Fox · Industrial / OT · IANA registry

Niagara Fox (building automation)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
4911TCP

Niagara Foxs · Industrial / OT · Application default

Niagara Fox over TLS (default)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

YesDo not expose directly to the internet
2222UDP

EtherNet/IP (implicit) · Industrial / OT · IANA registry

EtherNet/IP implicit I/O messaging

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
44818TCP/UDP

EtherNet/IP (explicit) · Industrial / OT · IANA registry

EtherNet/IP explicit messaging (CIP)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
2404TCP

IEC 60870-5-104 · Industrial / OT · IANA registry

IEC 60870-5-104 (power and SCADA telecontrol)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
4840TCP

OPC UA · Industrial / OT · IANA registry

OPC UA binary protocol (opc.tcp); security mode is configurable

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

OptionalDo not expose directly to the internet
5094TCP/UDP

HART-IP · Industrial / OT · IANA registry

HART-IP (field device communication)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
20000TCP/UDP

DNP3 · Industrial / OT · IANA registry

DNP3 (power and water SCADA)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
34962TCP/UDP

PROFINET RT · Industrial / OT · IANA registry

PROFINET real-time I/O

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
34963TCP/UDP

PROFINET RTM · Industrial / OT · IANA registry

PROFINET (profinet-rtm registration)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
34964TCP/UDP

PROFINET CM · Industrial / OT · IANA registry

PROFINET context management

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
47808UDP

BACnet/IP · Industrial / OT · IANA registry

BACnet/IP (building automation)

Industrial/OT protocol: usually has no authentication or encryption. Do not expose directly to the internet; segment the network and use a firewall and a separate demilitarised zone (DMZ).

NoDo not expose directly to the internet
1883TCP

MQTT · Messaging · IANA registry

MQTT, unencrypted

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
8883TCP

MQTT over TLS · Messaging · IANA registry

MQTT over TLS

Encrypted channel: keep certificates and the TLS version up to date.

YesOnly if protected
5671TCP

AMQPS · Messaging · IANA registry

AMQP over TLS

Message broker: enable authentication and TLS; allow access from the internal network only.

YesDo not expose directly to the internet
5672TCP

AMQP · Messaging · IANA registry

AMQP (RabbitMQ default)

Message broker: enable authentication and TLS; allow access from the internal network only.

OptionalDo not expose directly to the internet
9092TCP

Kafka · Messaging · Application default

Apache Kafka broker (default)

Message broker: enable authentication and TLS; allow access from the internal network only.

OptionalDo not expose directly to the internet
2181TCP

ZooKeeper · Messaging · Application default

Apache ZooKeeper client connection (default)

Message broker: enable authentication and TLS; allow access from the internal network only.

OptionalDo not expose directly to the internet
4222TCP

NATS · Messaging · Application default

NATS client connection (default)

Message broker: enable authentication and TLS; allow access from the internal network only.

OptionalDo not expose directly to the internet
5060TCP/UDP

SIP · Messaging · IANA registry

SIP signalling (VoIP), unencrypted

A target of brute force and toll fraud: use authentication, rate limiting and a session border controller (SBC).

NoOnly if protected
5061TCP

SIP over TLS · Messaging · IANA registry

SIP signalling over TLS

A target of brute force and toll fraud: use authentication, rate limiting and a session border controller (SBC).

YesOnly if protected
5222TCP

XMPP · Messaging · IANA registry

XMPP client connection (instant messaging)

A constant target of password guessing: use key-based authentication or MFA, IP restriction and rate limiting.

OptionalOnly if protected
53TCP/UDP

DNS · Network management · IANA registry

Name resolution; large answers and zone transfers use TCP

May be public for an authoritative server; restrict recursion and apply response rate limiting.

NoOnly if protected
67UDP

DHCP sunucu (BOOTP) · Network management · IANA registry

DHCP server side

Local network protocol: do not expose to the internet; block at the perimeter firewall.

NoDo not expose directly to the internet
68UDP

DHCP istemci · Network management · IANA registry

DHCP client side

Local network protocol: do not expose to the internet; block at the perimeter firewall.

NoDo not expose directly to the internet
69UDP

TFTP · Network management · IANA registry

Simple file transfer without authentication (device firmware, PXE)

An old, weak protocol: use a modern, authenticated and encrypted alternative instead.

NoDo not expose directly to the internet
123UDP

NTP · Network management · IANA registry

Network time synchronisation (NTP)

Can be abused in UDP reflection/amplification attacks; open it only to the sources that need it.

NoOnly if protected
161UDP

SNMP · Network management · IANA registry

SNMP queries (v3 offers authentication and encryption)

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
162UDP

SNMP trap · Network management · IANA registry

SNMP trap and inform notifications

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
179TCP

BGP · Network management · IANA registry

Border Gateway Protocol (BGP)

Routing protocol: run it only with known peers, with authentication and ACLs; apply prefix filters.

NoDo not expose directly to the internet
514UDP

Syslog · Network management · IANA registry

Syslog log forwarding (UDP)

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
137UDP

NetBIOS-NS · Network management · IANA registry

NetBIOS name service

A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1.

NoDo not expose directly to the internet
138UDP

NetBIOS-DGM · Network management · IANA registry

NetBIOS datagram service

A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1.

NoDo not expose directly to the internet
135TCP

MSRPC · Network management · IANA registry

Windows RPC endpoint mapper

A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1.

NoDo not expose directly to the internet
520UDP

RIP · Network management · IANA registry

RIP routing

Routing protocol: run it only with known peers, with authentication and ACLs; apply prefix filters.

NoDo not expose directly to the internet
5353UDP

mDNS · Network management · IANA registry

Multicast DNS on the local network (mDNS)

Local network protocol: do not expose to the internet; block at the perimeter firewall.

NoDo not expose directly to the internet
2375TCP

Docker API · Network management · IANA registry

Docker Engine API, unencrypted

A management API gives full control: never expose it to the internet without authentication or encryption.

NoDo not expose directly to the internet
2376TCP

Docker API (TLS) · Network management · IANA registry

Docker Engine API over TLS

A management API gives full control: never expose it to the internet without authentication or encryption.

YesDo not expose directly to the internet
6443TCP

Kubernetes API · Network management · Application default

Kubernetes API server (default)

A management API gives full control: never expose it to the internet without authentication or encryption.

YesDo not expose directly to the internet
2379TCP

etcd · Network management · IANA registry

etcd client connection

A management API gives full control: never expose it to the internet without authentication or encryption.

OptionalDo not expose directly to the internet
9090TCP

Prometheus · Network management · Application default

Prometheus monitoring server (default)

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
5601TCP

Kibana · Network management · Application default

Kibana interface (default)

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
10050TCP

Zabbix agent · Network management · IANA registry

Zabbix agent

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
10051TCP

Zabbix trapper · Network management · IANA registry

Zabbix server / trapper

Management interface: make it reachable only from the management network; do not expose to the internet.

OptionalDo not expose directly to the internet
20TCP

FTP data · File transfer · IANA registry

FTP data connection (active mode)

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
21TCP

FTP · File transfer · IANA registry

FTP control connection

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
989TCP

FTPS data · File transfer · IANA registry

FTP data connection over TLS (implicit)

Encrypted channel: keep certificates and the TLS version up to date.

YesOnly if protected
990TCP

FTPS · File transfer · IANA registry

FTP control connection over TLS (implicit)

Encrypted channel: keep certificates and the TLS version up to date.

YesOnly if protected
111TCP/UDP

RPC portmapper · File transfer · IANA registry

Sun RPC portmapper (used by NFS)

Local network protocol: do not expose to the internet; block at the perimeter firewall.

NoDo not expose directly to the internet
139TCP

NetBIOS-SSN · File transfer · IANA registry

NetBIOS session service (legacy SMB)

A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1.

NoDo not expose directly to the internet
445TCP

SMB · File transfer · IANA registry

SMB/CIFS file and printer sharing

A frequent attack target and lateral-movement path: do not expose to the internet, keep systems patched, disable SMBv1.

OptionalDo not expose directly to the internet
2049TCP/UDP

NFS · File transfer · IANA registry

Network File System (NFS)

NFS: expose only to a trusted network; restrict clients and consider Kerberos-based security.

OptionalDo not expose directly to the internet
873TCP

rsync · File transfer · IANA registry

rsync file synchronisation (daemon mode)

Unencrypted: data and passwords can be read on the network. Use the encrypted counterpart (or TLS).

NoDo not expose directly to the internet
3260TCP

iSCSI · File transfer · IANA registry

iSCSI storage target

Storage network: keep it on a separate network; use CHAP and IP restrictions.

NoDo not expose directly to the internet

Verify against the IANA service name and port number registry and the application documentation.

Port ranges

Well-known ports (0–1023)
System ports: basic services assigned by IANA (HTTP, SSH, SMTP...). On most operating systems listening on them needs privileges.
Registered ports (1024–49151)
Ports applications have registered with IANA (databases, protocols). Many products' defaults are here.
Dynamic / private ports (49152–65535)
The unassigned range: for clients' ephemeral source ports and private use. Some operating systems use a different ephemeral range.

Data and assumptions

  • Source: the "IANA registry" label marks a known assignment in the IANA service name and port number registry; "Application default" marks a product's common default port, for which the IANA entry may differ.
  • The protocol column shows the port's typical use; some ports are registered for both TCP and UDP or vary by application.
  • "Encrypted": Yes = the channel is encrypted by default, No = unencrypted, Optional = depends on version or configuration (STARTTLS, TLS setting).
  • "Do not expose directly to the internet" is a general principle, not a firm verdict for every environment; always weigh access against need, authentication and network segmentation.

Search and filters run in your browser; what you type is not sent to a server and not stored.

This guide is for general information, is not exhaustive and does not replace product-specific configuration: before opening or closing a port, verify it against the IANA registry and the documentation of the application concerned. The security notes are general good practice; they give no audit or compliance assurance.

Shall we review your firewall rules, network segmentation and OT/IT boundary together?

Request a meeting

01

How to use

  1. A

    Type a port number, a service name or a range (e.g. 8000-8100) in the search box.

  2. B

    Filter by category and protocol; if you like, show only those that should not face the internet directly.

  3. C

    Read the encryption and internet-exposure warning on each row; copy the visible table as CSV and verify the rules against your own documentation.

02

What a port is and what the ranges mean

A port is a 16-bit number (0–65535) that tells apart the services on one IP address. TCP and UDP ports are separate: the same number can belong to different services in the two protocols. IANA groups the numbers into three ranges: well-known (0–1023), registered (1024–49151) and dynamic/private (49152–65535).

A port being registered with IANA does not mean the service will only use that port; administrators can move a service to another port and products can choose different defaults. That is why the table states the source (IANA registry or application default) separately.

03

Why the "do not expose directly to the internet" warning

Databases, remote desktop (RDP), file sharing (SMB), management APIs and industrial/OT protocols become frequent attack targets when opened to remote, unauthenticated sources. Many OT protocols such as Modbus, S7comm, DNP3, EtherNet/IP and BACnet have no authentication or encryption by design; anyone who can reach an internet-facing PLC can read or write it.

In practice it is advisable to keep access behind a VPN, a remote access gateway or a DMZ, to segment the network into IT and OT, and to allow only the source addresses that need access. The warning in the table is a starting point; assess the rules for your own environment.

04

Encrypted and unencrypted protocols

Old protocols such as HTTP, FTP, Telnet, POP3 and SNMPv1/v2c send data and passwords in the clear; anyone listening on the network can read them. Most have a TLS-protected counterpart (HTTPS, FTPS/SFTP, SSH, POP3S/IMAPS, SNMPv3). Rows marked "Optional" depend on version or configuration (e.g. STARTTLS); do not assume encryption is on, check your configuration.

Being encrypted does not make exposing a service to the internet safe: authentication, patch status and access restrictions remain decisive.

FAQ

Is my search sent anywhere?
No. Search and filters run in your browser; what you type is not sent to a server and is not stored.
Is the table complete?
No. It contains a selection of common services and industrial/OT protocols whose source is certain. For a port not on the list, check the IANA registry and the product documentation.
What is the difference between "IANA registry" and "Application default"?
An IANA registry entry is the official assignment of a service name and port number. An application default is the common port a product uses on installation; IANA may have assigned it to another service, and it can be changed in the settings.
Which OT protocols are unencrypted?
Modbus TCP, classic S7comm, DNP3, IEC 60870-5-104, EtherNet/IP, BACnet/IP and classic PROFINET offer no authentication or encryption. OPC UA has security modes but they must be configured; secure variants of some protocols are defined in separate specifications.
What should I do if I must expose a port to the internet?
First consider an alternative (VPN, remote access gateway, reverse proxy). If it is still necessary, restrict the source IP, use strong authentication and TLS, keep the software up to date, and log and monitor access.
What is the dynamic port range used for?
The 49152–65535 range is unassigned: it is used for clients' ephemeral source ports and private use. Some systems define different ephemeral ranges; check your own operating system's setting.

Do your firewall and network segmentation need a review?

Let us do the design and rule review together for corporate networks, OT/SCADA segmentation, remote access and cloud connections. In a free discovery call we discuss your current state.