Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.2.2 (10 of 20 in this unit)43 of 84 in the Network Fundamentals course

Common ports to know

The port numbers behind everyday services, and which ones use TCP, UDP or both.

Beginner · 5 min read

A well-known port is a port number in the range 0 to 1023 that is assigned to a standard service, such as 22 for SSH, 53 for DNS or 443 for HTTPS. A server listens on that port by default, so clients know where to send their requests.

In simple terms: It is the usual “door number” of a service. A browser knows that a secure website listens on port 443, so that is where it knocks.

A situation

A firewall rule says "permit TCP to port 22, deny everything else". A help desk ticket says "users cannot reach the server on 3389". A packet capture shows a lot of traffic on UDP 53. To understand any of these quickly, you need to know which service uses which port.

What it is

A well-known port is a fixed port number that a service listens on by default. The client sends its request to that port, so it always knows where to find the service. Some services use TCP, some use UDP, and a few use both.

Admin PC10.1.1.50Core switchR1SSH 22DNSUDP 53NTPUDP 123
  1. 1. SSH to the router. Every character of a login session must arrive complete and in order, so SSH uses TCP.
  2. 2. DNS lookup. It is a short question and a short answer, so UDP is enough.
  3. 3. Time check. NTP sends small, regular time requests over UDP. A late answer would give the wrong time, so there is no point resending; the client simply asks again later.

The ports to learn

PortServiceTransportUsed for
20, 21FTP (data, control)TCPFile transfer
22SSHTCPSecure remote login; also SCP and SFTP
23TelnetTCPRemote login with no encryption
25SMTPTCPSending email between servers
53DNSUDP and TCPName lookups (UDP); large answers and zone transfers (TCP)
67, 68DHCP (server, client)UDPHanding out IP addresses
69TFTPUDPSimple file transfer, e.g. IOS images and configs
80HTTPTCPWeb pages without encryption
110POP3TCPDownloading email
123NTPUDPTime synchronisation
143IMAPTCPReading email kept on the server
161, 162SNMP (queries, traps)UDPMonitoring network devices
443HTTPSTCP (and UDP for HTTP/3)Encrypted web pages
514SyslogUDPSending log messages to a server
3389RDPTCP (and UDP)Windows remote desktop

💡 Memory trick: several ports come in order. FTP is 20/21, then SSH 22, Telnet 23 and SMTP 25. DHCP is 67/68, then TFTP 69. SNMP is 161/162.

Why some use TCP and others UDP

The choice depends on the job. Services that move files, web pages or login sessions need every byte, so they use TCP. Services that send small, quick messages (DNS, DHCP, NTP, SNMP, syslog) use UDP. Each message usually fits in one datagram, and if it is lost, the application simply asks again or sends the next one.

DHCP has one more reason to use UDP. A new client has no IP address yet, so it has to broadcast its request. A TCP handshake needs a known address at each end, so it cannot work with a broadcast. UDP can.

How to verify it

A Cisco device can show which ports it is listening on itself. The output below is based on Cisco documentation, not captured from a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show control-plane host open-ports
Active internet connections (servers and established)
Prot        Local Address      Foreign Address                  Service    State
 tcp                 *:22                  *:0               SSH-Server   LISTEN
 tcp                 *:23                  *:0                   Telnet   LISTEN
 udp                *:123                  *:0                      NTP   LISTEN
 udp                *:161                  *:0                  IP SNMP   LISTEN
 udp                *:162                  *:0                  IP SNMP   LISTEN
What to look for: the Prot, Local Address and State columns. This router is listening for SSH (TCP 22) and Telnet (TCP 23), and for NTP (UDP 123) and SNMP (UDP 161 and 162). Telnet sends everything unencrypted, so seeing it here is a sign that you should disable it and use only SSH.

Check yourself

Predict · scenario 1

You are copying an IOS image from a TFTP server, but a firewall is in the way. Which port and protocol must the firewall allow to the TFTP server?

Predict · scenario 2

A firewall allows only TCP 443 out to the internet. Which of these connections can still leave the network?

Predict · scenario 3

A new laptop joins the network and needs an IP address. Why does DHCP use UDP for this instead of TCP?