Common Network Port Numbers Flashcards: Protocols, TCP/UDP & Uses
Study 88 cards on common network ports, TCP/UDP transports, service uses, port ranges, and practical protocol distinctions.
About this deck
Build a practical map of common network service ports with 88 independently authored cards. Twelve foundation and distinction cards cover port roles, IANA ranges, independent TCP and UDP namespaces, assignment limits, conventional versus configured ports, client source ports, DNS transport behavior, DHCP endpoints, FTP channels, and common implicit-TLS pairs.
The remaining 76 cards practice 38 mappings in both useful directions: service → conventional or registered port, transport, and concise use; and port/transport → service and concise use. Coverage includes FTP control and active-mode data, SSH/SFTP, Telnet, SMTP relay, DNS, DHCPv4 server and client endpoints, TFTP, HTTP, Kerberos, POP3, NTP, the three NetBIOS services, IMAP, SNMP queries and notifications, BGP, LDAP, HTTPS including HTTP/3, direct-hosted SMB, IKE, syslog, SMTP submission, LDAPS, IMAPS, POP3S, Microsoft SQL Server, L2TP, PPTP, RADIUS authentication, MySQL, RDP, IPsec NAT Traversal, SIP, and PostgreSQL.
This is a focused recall deck, not a copy of the full IANA registry. It excludes exhaustive assignments, port-scanning or attack instructions, firewall policy, every vendor-specific alternate, dynamic service-discovery inventories, and the claim that a port number proves which application produced observed traffic. Registered, default, conventional, and common-use wording stays explicit because services can be reconfigured or negotiated elsewhere.
The sequence establishes the port model first, then mixes web, email, infrastructure, remote-access, file-transfer, network-management, directory, VPN, voice, Windows, and database families. Opposite directions for the same mapping stay at least 38 intervening cards apart. Near-duplicate DNS, DHCP, FTP, SNMP, NetBIOS, and IPsec cues keep at least three unrelated cards between them, and the TLS-pair distinction stays at least three unrelated cards from its closest overlapping mapping. The review scheduler handles continued spacing after installation.
Open Study Contributor independently authored the prompts, answers, mapping choices, organization, metadata, and cover from common networking knowledge checked against the current IANA Service Name and Transport Protocol Port Number Registry, relevant RFCs, and official vendor documentation. Organization and product names identify protocols, services, or sources only; no affiliation or endorsement is claimed. No competitor card text, certification questions, answer keys, course text, or source prose was copied.
The CC0 label applies to the original prompts, answers, organization, metadata, and generated cover to the extent applicable rights exist. It does not claim ownership of protocol facts, standards, organization names, product names, or third-party source material.
Cards in this deck
Card 1
Question
What does a transport-layer port number identify?
Answer
An application endpoint within a host for one transport protocol. The IP addresses, transport protocol, and source and destination ports together identify a communication flow.
Card 2
Question
Are TCP port 53 and UDP port 53 the same port?
Answer
No. TCP and UDP have independent 16-bit port namespaces, so 53/TCP and 53/UDP are separate transport endpoints.
Card 3
Question
What is the IANA System Port range?
Answer
0–1023. These are also called Well-Known Ports and are assigned by IANA under the stricter System Port procedures.
Card 4
Question
What is the IANA User Port range?
Answer
1024–49151. These are also called Registered Ports and may be assigned by IANA to services.
Card 5
Question
What is the IANA Dynamic or Private Port range?
Answer
49152–65535. IANA does not assign ports in this range; systems commonly use it for temporary or private endpoints.
Card 6
Question
Does an IANA port assignment prove what observed traffic is—or that it is safe?
Answer
No. A registration is a naming convention, not traffic identification, authorization, or a security verdict. Verify the actual protocol and context.
Card 7
Question
Must a service use its registered or conventional port?
Answer
No. Administrators and applications can choose another port, negotiate one dynamically, or discover it through mechanisms such as DNS SRV records.
Card 8
Question
What port roles are typical in a client-server connection?
Answer
The server usually listens on a known destination port, while the client uses a temporary source port. Either side can be configured differently.
Card 9
Question
SSH and SFTP — common server port and transport?
Answer
TCP 22. SSH provides encrypted remote access, and SFTP normally runs as a subsystem inside the same SSH connection.
Card 10
Question
53/UDP or 53/TCP — which service?
Answer
DNS. Routine queries often use UDP, while full DNS implementations also support TCP; zone transfers use TCP.
Card 11
Question
SMTP relay between mail servers — common port and transport?
Answer
TCP 25. SMTP uses it for server-to-server mail transfer; user mail submission normally uses port 587 or implicit TLS on 465.
Card 12
Question
HTTP without TLS — conventional port and transport?
Answer
TCP 80 for conventional HTTP/1.1 and HTTP/2 connections. The service can be configured on another port.
Card 13
Question
67/UDP — which DHCPv4 endpoint?
Answer
The DHCPv4 server endpoint. Clients send server-directed DHCP messages to UDP port 67.
Card 14
Question
21/TCP — which service and channel?
Answer
FTP control. It carries commands and replies; file data uses a separate connection.
Card 15
Question
SNMP requests and responses — common agent port and transport?
Answer
UDP 161. Managers commonly send queries to an SNMP agent there; other SNMP transports exist.
Card 16
Question
1433/TCP — which database service?
Answer
Microsoft SQL Server's default instance. TCP 1433 is the default Database Engine port, but named or custom instances may use another port.
Card 17
Question
23/TCP — which remote-access protocol?
Answer
Telnet. It provides a plaintext remote terminal session and does not protect credentials or traffic with encryption.
Card 18
Question
NTP — usual port and transport?
Answer
UDP 123. NTP normally uses UDP for time synchronization; IANA also has a TCP 123 registration, but that is not the usual NTP transport.
Card 19
Question
Why must a general-purpose DNS implementation support both UDP and TCP?
Answer
UDP handles most routine queries efficiently, while TCP handles cases such as zone transfers and responses that do not fit the chosen UDP path. Both use port 53.
Card 20
Question
POP3 — conventional port and transport?
Answer
TCP 110. POP3 retrieves mail; it can upgrade with STLS, while implicit TLS uses TCP 995.
Card 21
Question
443/TCP or 443/UDP — which web service?
Answer
HTTPS. HTTP/1.1 and HTTP/2 normally use TLS over TCP 443; HTTP/3 uses QUIC over UDP 443.
Card 22
Question
DHCPv4 client endpoint — port and transport?
Answer
UDP 68. Servers send client-directed DHCPv4 messages to port 68.
Card 23
Question
69/UDP — which file-transfer protocol?
Answer
TFTP. A client sends the initial read or write request to UDP 69; the transfer then continues with a server-selected UDP transfer identifier.
Card 24
Question
162/UDP — which network-management traffic?
Answer
SNMP notifications, traditionally called traps. Notification receivers commonly listen on UDP 162.
Card 25
Question
MySQL classic protocol — default port and transport?
Answer
TCP 3306. It is the default for classic MySQL client-server connections and can be reconfigured.
Card 26
Question
How do FTP control, active-mode data, and passive-mode data ports differ?
Answer
Control uses TCP 21. The server side of the default active-mode data connection uses TCP 20, while passive mode negotiates another server port.
Card 27
Question
3389/TCP or 3389/UDP — which remote-desktop service?
Answer
Microsoft Remote Desktop Protocol (RDP). TCP and UDP 3389 are the standard defaults, and the listening port can be changed.
Card 28
Question
Syslog's conventional UDP transport — port?
Answer
UDP 514. Classic syslog over UDP has no delivery guarantee; TCP 514 is registered to the shell service, not syslog.
Card 29
Question
How do DHCPv4 server and client ports pair up?
Answer
UDP 67 is the server port, and UDP 68 is the client port. Client-to-server messages target 67; server-to-client messages target 68.
Card 30
Question
IMAP — conventional port and transport?
Answer
TCP 143. IMAP accesses and manages mail on a server; implicit TLS uses TCP 993.
Card 31
Question
445/TCP — which file-sharing service?
Answer
Direct-hosted SMB. Modern SMB servers commonly listen on TCP 445 without the older NetBIOS session layer.
Card 32
Question
88/UDP or 88/TCP — which authentication protocol?
Answer
Kerberos. Clients and Key Distribution Centers support both transports; TCP also handles requests or replies too large for UDP.
Card 33
Question
FTP's default active-mode data connection — server-side port and transport?
Answer
TCP 20. This is the server's default source port for active-mode data; passive FTP negotiates another server port.
Card 34
Question
BGP — standard operational port and transport?
Answer
TCP 179. RFC 4271 defines BGP peer sessions over TCP; IANA separately retains a UDP 179 registry entry.
Card 35
Question
5432/TCP — which database service?
Answer
PostgreSQL. TCP 5432 is the customary default server port, but an installation can choose another port.
Card 36
Question
IKE for IPsec — initial port and transport?
Answer
UDP 500. IKE normally begins there; NAT traversal commonly moves subsequent IKE and encapsulated ESP traffic to UDP 4500.
Card 37
Question
NetBIOS Name Service — common port and transport?
Answer
UDP 137. It supports NetBIOS name registration and lookup; direct-hosted modern SMB does not require it.
Card 38
Question
587/TCP — which email role?
Answer
SMTP message submission. Mail clients normally submit outgoing mail to a submission server there, often with STARTTLS; server relay remains on TCP 25.
Card 39
Question
389/TCP — which directory protocol?
Answer
LDAP. Ordinary connection-oriented LDAP commonly uses TCP 389; IANA also registers UDP 389 for connectionless LDAP.
Card 40
Question
L2TP — common port and transport?
Answer
UDP 1701. L2TP carries tunnel control and data but does not provide encryption by itself; deployments often pair it with IPsec.
Card 41
Question
138/UDP — which NetBIOS service?
Answer
NetBIOS Datagram Service. It carries connectionless NetBIOS datagrams, historically used in NetBIOS over TCP/IP environments.
Card 42
Question
IMAPS — default port and transport?
Answer
TCP 993. It starts IMAP with an immediate TLS handshake for encrypted mail access.
Card 43
Question
636/TCP — which directory-service convention?
Answer
LDAPS, the commonly used implicit-TLS port for LDAP. LDAP can also negotiate TLS on TCP 389.
Card 44
Question
1723/TCP — which VPN control protocol?
Answer
PPTP control. PPTP uses TCP 1723 for control, while tunneled PPP data travels in GRE—not on TCP or UDP port 47.
Card 45
Question
NetBIOS Session Service — common port and transport?
Answer
TCP 139. It provides connection-oriented NetBIOS sessions and historically carried SMB before direct-hosted SMB on TCP 445.
Card 46
Question
995/TCP — which mail-access service?
Answer
POP3S. It starts POP3 with an immediate TLS handshake for encrypted mail retrieval.
Card 47
Question
RADIUS authentication and authorization — standard port and transport?
Answer
UDP 1812. RADIUS accounting normally uses the separate UDP port 1813.
Card 48
Question
IPsec NAT Traversal — port and transport?
Answer
UDP 4500. It carries IKE and UDP-encapsulated ESP when NAT traversal is in use.
Card 49
Question
5060/UDP or 5060/TCP — which signaling protocol?
Answer
SIP. It commonly uses UDP or TCP 5060 for session signaling; SIP over TLS conventionally uses TCP 5061.
Card 50
Question
Which common dedicated ports distinguish plaintext or STARTTLS-capable services from implicit-TLS variants?
Answer
HTTP 80 ↔ HTTPS 443; IMAP 143 ↔ IMAPS 993; POP3 110 ↔ POP3S 995; LDAP 389 ↔ LDAPS 636. A port alone does not prove that TLS is configured correctly.
Card 51
Question
22/TCP — which secure remote-access service?
Answer
SSH. It supports encrypted remote login, command execution, tunneling, and file-transfer tools such as SFTP.
Card 52
Question
DNS — registered port and required general-purpose transports?
Answer
Port 53 over UDP and TCP. Most ordinary queries start with UDP, while TCP is required for full implementations and used for zone transfers and other larger exchanges.
Card 53
Question
25/TCP — which email function?
Answer
SMTP mail relay and delivery between servers. End-user clients normally submit new mail on TCP 587 or TCP 465 instead.
Card 54
Question
80/TCP — which conventional web service?
Answer
HTTP without TLS. It is the conventional port for HTTP/1.1 and HTTP/2, although servers can listen elsewhere.
Card 55
Question
DHCPv4 server endpoint — port and transport?
Answer
UDP 67. DHCPv4 clients direct server-bound messages to that port.
Card 56
Question
FTP control — server port and transport?
Answer
TCP 21. Commands and replies use the persistent control connection; data travels on a separate connection.
Card 57
Question
161/UDP — which network-management traffic?
Answer
SNMP requests and responses. Managed agents commonly listen on UDP 161 for manager queries.
Card 58
Question
Microsoft SQL Server default instance — default port and transport?
Answer
TCP 1433. Named instances may use dynamic or custom ports, with SQL Server Browser commonly using UDP 1434 for discovery.
Card 59
Question
Telnet — conventional port and transport?
Answer
TCP 23. Telnet carries terminal traffic in plaintext, so SSH is the usual secure replacement.
Card 60
Question
123/UDP — which time service?
Answer
NTP. Network Time Protocol commonly synchronizes clocks over UDP 123.
Card 61
Question
110/TCP — which mail-access protocol?
Answer
POP3. It downloads or retrieves mail from a server; implicit TLS uses TCP 995.
Card 62
Question
HTTPS — common port and transports?
Answer
Port 443: TCP for HTTP/1.1 and HTTP/2 over TLS, and UDP for HTTP/3 over QUIC.
Card 63
Question
68/UDP — which DHCPv4 endpoint?
Answer
The DHCPv4 client endpoint. Servers direct client-bound DHCP messages to UDP 68.
Card 64
Question
TFTP — initial request port and transport?
Answer
UDP 69. Only the initial request targets 69; the server chooses another UDP transfer identifier for the data exchange.
Card 65
Question
SNMP traps and other notifications — common receiver port and transport?
Answer
UDP 162. SNMP notification receivers commonly listen there.
Card 66
Question
3306/TCP — which database protocol?
Answer
The classic MySQL protocol. TCP 3306 is its default client-server port and is configurable.
Card 67
Question
RDP — standard port and transports?
Answer
TCP and UDP 3389. Microsoft Remote Desktop uses them by default, though administrators can change the listening port.
Card 68
Question
514/UDP — which logging protocol?
Answer
Syslog over UDP. It is a conventional lightweight transport without delivery guarantees; secure syslog commonly uses another transport and port.
Card 69
Question
143/TCP — which mail-access protocol?
Answer
IMAP. It manages mail on the server; implicit TLS uses TCP 993.
Card 70
Question
Direct-hosted SMB — common server port and transport?
Answer
TCP 445. It carries SMB directly over TCP without the legacy NetBIOS Session Service on TCP 139.
Card 71
Question
Kerberos KDC traffic — port and transports?
Answer
UDP and TCP 88. Conforming clients and Key Distribution Centers support both, with TCP available for larger exchanges.
Card 72
Question
20/TCP — which FTP role?
Answer
The server side of FTP's default active-mode data connection. Passive mode negotiates a different server port.
Card 73
Question
179/TCP — which routing protocol?
Answer
BGP. Border Gateway Protocol peers use a TCP session to exchange routing information.
Card 74
Question
PostgreSQL — customary default port and transport?
Answer
TCP 5432. PostgreSQL servers normally use it unless configured or compiled with another default.
Card 75
Question
500/UDP — which IPsec setup protocol?
Answer
IKE, the Internet Key Exchange protocol. It negotiates IPsec security associations and commonly moves to UDP 4500 when NAT traversal is used.
Card 76
Question
137/UDP — which NetBIOS service?
Answer
NetBIOS Name Service. It handles name registration and lookup in legacy NetBIOS over TCP/IP environments.
Card 77
Question
SMTP message submission — normal port and transport?
Answer
TCP 587. It separates authenticated client submission from server-to-server SMTP relay on TCP 25; STARTTLS is commonly used.
Card 78
Question
LDAP — conventional connection-oriented port and transport?
Answer
TCP 389. Connectionless LDAP can use UDP 389, and implicit-TLS LDAP commonly uses TCP 636.
Card 79
Question
1701/UDP — which tunneling protocol?
Answer
L2TP. It tunnels Layer 2 traffic but needs a separate security layer such as IPsec when confidentiality is required.
Card 80
Question
NetBIOS Datagram Service — common port and transport?
Answer
UDP 138. It provides connectionless NetBIOS datagram delivery.
Card 81
Question
993/TCP — which mail-access service?
Answer
IMAPS. It begins IMAP with implicit TLS for encrypted access to mail stored on a server.
Card 82
Question
LDAPS — commonly used implicit-TLS port and transport?
Answer
TCP 636. LDAP can instead use TCP 389 and negotiate TLS with StartTLS.
Card 83
Question
PPTP control — port and transport?
Answer
TCP 1723. The control channel uses that port; PPP payloads travel through GRE, which is IP protocol 47 rather than port 47.
Card 84
Question
139/TCP — which NetBIOS service?
Answer
NetBIOS Session Service. It historically carried SMB sessions; direct-hosted SMB commonly uses TCP 445 instead.
Card 85
Question
POP3S — default port and transport?
Answer
TCP 995. It uses implicit TLS for encrypted POP3 mail retrieval.
Card 86
Question
1812/UDP — which AAA service?
Answer
RADIUS authentication and authorization. RADIUS accounting normally uses UDP 1813.
Card 87
Question
4500/UDP — which IPsec function?
Answer
IPsec NAT Traversal. It carries IKE and UDP-encapsulated ESP across network address translation.
Card 88
Question
SIP signaling without implicit TLS — common port and transports?
Answer
UDP or TCP 5060. SIP over TLS conventionally uses TCP 5061, and media streams use separately negotiated ports.
88 cards
Common Network Port Numbers Flashcards: Protocols, TCP/UDP & Uses
Flashcards opens so you can start studying.