A situation
A firewall rule says "permit TCP to port 22, deny everything else". A help desk ticket says "users cannot reach the server on 3389". A packet capture shows a lot of traffic on UDP 53. To understand any of these quickly, you need to know which service uses which port.
What it is
A well-known port is a fixed port number that a service listens on by default. The client sends its request to that port, so it always knows where to find the service. Some services use TCP, some use UDP, and a few use both.
- 1. SSH to the router. Every character of a login session must arrive complete and in order, so SSH uses TCP.
- 2. DNS lookup. It is a short question and a short answer, so UDP is enough.
- 3. Time check. NTP sends small, regular time requests over UDP. A late answer would give the wrong time, so there is no point resending; the client simply asks again later.
The ports to learn
| Port | Service | Transport | Used for |
|---|---|---|---|
20, 21 | FTP (data, control) | TCP | File transfer |
22 | SSH | TCP | Secure remote login; also SCP and SFTP |
23 | Telnet | TCP | Remote login with no encryption |
25 | SMTP | TCP | Sending email between servers |
53 | DNS | UDP and TCP | Name lookups (UDP); large answers and zone transfers (TCP) |
67, 68 | DHCP (server, client) | UDP | Handing out IP addresses |
69 | TFTP | UDP | Simple file transfer, e.g. IOS images and configs |
80 | HTTP | TCP | Web pages without encryption |
110 | POP3 | TCP | Downloading email |
123 | NTP | UDP | Time synchronisation |
143 | IMAP | TCP | Reading email kept on the server |
161, 162 | SNMP (queries, traps) | UDP | Monitoring network devices |
443 | HTTPS | TCP (and UDP for HTTP/3) | Encrypted web pages |
514 | Syslog | UDP | Sending log messages to a server |
3389 | RDP | TCP (and UDP) | Windows remote desktop |
💡 Memory trick: several ports come in order. FTP is 20/21, then SSH 22, Telnet 23 and SMTP 25. DHCP is 67/68, then TFTP 69. SNMP is 161/162.
Why some use TCP and others UDP
The choice depends on the job. Services that move files, web pages or login sessions need every byte, so they use TCP. Services that send small, quick messages (DNS, DHCP, NTP, SNMP, syslog) use UDP. Each message usually fits in one datagram, and if it is lost, the application simply asks again or sends the next one.
DHCP has one more reason to use UDP. A new client has no IP address yet, so it has to broadcast its request. A TCP handshake needs a known address at each end, so it cannot work with a broadcast. UDP can.
How to verify it
A Cisco device can show which ports it is listening on itself. The output below is based on Cisco documentation, not captured from a lab device.
R1#show control-plane host open-ports Active internet connections (servers and established) Prot Local Address Foreign Address Service State tcp *:22 *:0 SSH-Server LISTEN tcp *:23 *:0 Telnet LISTEN udp *:123 *:0 NTP LISTEN udp *:161 *:0 IP SNMP LISTEN udp *:162 *:0 IP SNMP LISTEN
Check yourself
You are copying an IOS image from a TFTP server, but a firewall is in the way. Which port and protocol must the firewall allow to the TFTP server?
A firewall allows only TCP 443 out to the internet. Which of these connections can still leave the network?
A new laptop joins the network and needs an IP address. Why does DHCP use UDP for this instead of TCP?