A situation
Two people in the same office open the same website at the same moment. The web server sees two connections, both to its port 443. Even one person with three browser tabs can open three connections to that same port. How does the server keep all of these apart and send each reply to the right tab?
IP finds the host, the port finds the application
One computer runs many programs that use the network at the same time: a browser, an email app, a chat app and a game. They all share the same IP address, so delivery happens in two steps:
| Address | Layer | Identifies | Example |
|---|---|---|---|
| IP address | Network (Layer 3) | Which host (device) the packet is for | 203.0.113.10 |
| Port number | Transport (Layer 4) | Which application on that host gets the data | 443 (the web server program) |
💡 In simple terms: the IP address is the street address of a block of flats, and the port number is the flat number. The postman needs the street address to find the building and the flat number to find the right person inside.
What it is
A port number is a 16-bit number (0 to 65,535) in the TCP or UDP header. Every TCP segment and UDP datagram carries two of them:
- Destination port: which service the data is for, such as 443 for HTTPS.
- Source port: which program on the sender the data came from. The client's operating system normally picks an unused high number, often at random. This temporary number is called an ephemeral port.
When the server replies, it swaps the two: the source port becomes the destination port, and the destination port becomes the source port.
- 1. Request: source port 52000 (picked by the client), destination port 443 (HTTPS).
- 2. Reply: the server swaps them: source 443, destination 52000. The reply reaches the right browser tab.
This example ignores NAT. In a real home network, the router's NAT would also change the client's source address, and often its source port, on the way out, then reverse the change on the reply.
The three port ranges
IANA (the Internet Assigned Numbers Authority), the organisation that assigns internet numbers, divides ports into three ranges:
| Range | Name | Used for |
|---|---|---|
0–1023 | Well-known (system) ports | Common server services: HTTP 80, HTTPS 443, SSH 22, DNS 53 |
1024–49151 | Registered (user) ports | Services registered by companies or projects, such as RDP 3389 |
49152–65535 | Dynamic (private, ephemeral) ports | Temporary source ports picked by clients |
Real operating systems do not always follow the last range exactly. Windows (since Vista) and macOS use the IANA range 49152–65535, but most Linux systems pick source ports from 32768–60999 by default, and administrators can change these ranges. The idea is the same everywhere: an ephemeral port is a short-lived, high number that is used for one connection and freed when it closes.
| Source port | Destination port | |
|---|---|---|
| Client → server (request) | Ephemeral, e.g. 52000 | Well-known, e.g. 443 |
| Server → client (reply) | Well-known, 443 | Ephemeral, 52000 |
Sockets: four values name a connection
An IP address plus a port number is called a socket, for example 203.0.113.10:443. A connection has a socket at each end, so it is identified by four values, called the socket pair:
| Connection | Source IP | Source port | Destination IP | Destination port |
|---|---|---|---|---|
| Tab 1 | 192.168.1.20 | 52000 | 203.0.113.10 | 443 |
| Tab 2 | 192.168.1.20 | 52001 | 203.0.113.10 | 443 |
| Colleague | 192.168.1.31 | 52000 | 203.0.113.10 | 443 |
Every row differs in at least one value, so the server can keep the connections apart. The colleague even uses the same source port, 52000, but the source IP address is different, so it is still a separate connection. These four values plus the protocol (TCP or UDP) are often called the 5-tuple. Firewalls and NAT devices use it to track traffic.
Why it works this way
Fixed, well-known ports mean a client always knows where to find a service: a browser does not have to ask which port HTTPS uses. Different source ports give each new connection its own unique socket pair, so many connections to the same service never get mixed up. Choosing source ports at random also makes it harder for an attacker to guess and fake (spoof) a connection.
How to verify it
On a Cisco router, show tcp brief lists the TCP connections that end on the router itself, such as SSH sessions. The output below is based on Cisco documentation, not captured from a lab device.
R1#show tcp brief TCB Local Address Foreign Address (state) 6523A4FC 192.168.1.1.22 192.168.1.50.51544 ESTAB 65239A84 192.168.1.1.22 192.168.1.51.60212 ESTAB
Check yourself
Your laptop opens an SSH session, sending a segment from source port 50500 to destination port 22 on a server. Which ports does the server's reply use?
A firewall log shows incoming connections to TCP port 3389 (RDP). Which port range is that?
Two browser tabs on the same PC are both connected to 203.0.113.10:443. Which values together identify each TCP connection?