Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.2.1 (9 of 20 in this unit)42 of 84 in the Network Fundamentals course

Port numbers and sockets

Well-known, registered and dynamic ports, and how four values identify every connection.

Beginner · 7 min read

Port number is a 16-bit value (0 to 65,535) in the TCP or UDP header that identifies which application or service on a host the data belongs to. The source and destination ports, together with the two IP addresses, form a socket pair that identifies a single connection.

In simple terms: An IP address finds the computer; the port number finds the program on it, like a flat number in a block of flats.

A situation

Two people in the same office open the same website at the same moment. The web server sees two connections, both to its port 443. Even one person with three browser tabs can open three connections to that same port. How does the server keep all of these apart and send each reply to the right tab?

IP finds the host, the port finds the application

One computer runs many programs that use the network at the same time: a browser, an email app, a chat app and a game. They all share the same IP address, so delivery happens in two steps:

AddressLayerIdentifiesExample
IP addressNetwork (Layer 3)Which host (device) the packet is for203.0.113.10
Port numberTransport (Layer 4)Which application on that host gets the data443 (the web server program)

💡 In simple terms: the IP address is the street address of a block of flats, and the port number is the flat number. The postman needs the street address to find the building and the flat number to find the right person inside.

What it is

A port number is a 16-bit number (0 to 65,535) in the TCP or UDP header. Every TCP segment and UDP datagram carries two of them:

  • Destination port: which service the data is for, such as 443 for HTTPS.
  • Source port: which program on the sender the data came from. The client's operating system normally picks an unused high number, often at random. This temporary number is called an ephemeral port.

When the server replies, it swaps the two: the source port becomes the destination port, and the destination port becomes the source port.

Client192.168.1.20RouterWeb server203.0.113.10
  1. 1. Request: source port 52000 (picked by the client), destination port 443 (HTTPS).
  2. 2. Reply: the server swaps them: source 443, destination 52000. The reply reaches the right browser tab.

This example ignores NAT. In a real home network, the router's NAT would also change the client's source address, and often its source port, on the way out, then reverse the change on the reply.

The three port ranges

IANA (the Internet Assigned Numbers Authority), the organisation that assigns internet numbers, divides ports into three ranges:

RangeNameUsed for
0–1023Well-known (system) portsCommon server services: HTTP 80, HTTPS 443, SSH 22, DNS 53
1024–49151Registered (user) portsServices registered by companies or projects, such as RDP 3389
49152–65535Dynamic (private, ephemeral) portsTemporary source ports picked by clients

Real operating systems do not always follow the last range exactly. Windows (since Vista) and macOS use the IANA range 49152–65535, but most Linux systems pick source ports from 32768–60999 by default, and administrators can change these ranges. The idea is the same everywhere: an ephemeral port is a short-lived, high number that is used for one connection and freed when it closes.

Source portDestination port
Client → server (request)Ephemeral, e.g. 52000Well-known, e.g. 443
Server → client (reply)Well-known, 443Ephemeral, 52000

Sockets: four values name a connection

An IP address plus a port number is called a socket, for example 203.0.113.10:443. A connection has a socket at each end, so it is identified by four values, called the socket pair:

ConnectionSource IPSource portDestination IPDestination port
Tab 1192.168.1.2052000203.0.113.10443
Tab 2192.168.1.2052001203.0.113.10443
Colleague192.168.1.3152000203.0.113.10443

Every row differs in at least one value, so the server can keep the connections apart. The colleague even uses the same source port, 52000, but the source IP address is different, so it is still a separate connection. These four values plus the protocol (TCP or UDP) are often called the 5-tuple. Firewalls and NAT devices use it to track traffic.

Why it works this way

Fixed, well-known ports mean a client always knows where to find a service: a browser does not have to ask which port HTTPS uses. Different source ports give each new connection its own unique socket pair, so many connections to the same service never get mixed up. Choosing source ports at random also makes it harder for an attacker to guess and fake (spoof) a connection.

How to verify it

On a Cisco router, show tcp brief lists the TCP connections that end on the router itself, such as SSH sessions. The output below is based on Cisco documentation, not captured from a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show tcp brief
TCB       Local Address               Foreign Address             (state)
6523A4FC  192.168.1.1.22              192.168.1.50.51544          ESTAB
65239A84  192.168.1.1.22              192.168.1.51.60212          ESTAB
What to look for: Cisco writes a socket as address.port, so 192.168.1.1.22 means port 22 on 192.168.1.1. Both sessions use the router's SSH port 22 in Local Address, but each Foreign Address is a different client socket, so they are two separate connections. ESTAB means each connection is established.

Check yourself

Predict · scenario 1

Your laptop opens an SSH session, sending a segment from source port 50500 to destination port 22 on a server. Which ports does the server's reply use?

Predict · scenario 2

A firewall log shows incoming connections to TCP port 3389 (RDP). Which port range is that?

Predict · scenario 3

Two browser tabs on the same PC are both connected to 203.0.113.10:443. Which values together identify each TCP connection?