
Terrence Blake
The port number is a convention with a registry, and knowing which numbers are assigned tells you more about a system than any banner does. The lowest range is the system range. Then the registered ports, which are the ones with an assigned service. Then the dynamic range, which a system allocates to an outgoing connection and which is why an ephemeral port on the server is not the port you connected to. Three numbers are worth knowing cold. Twenty-two is remote access and appears in every firewall rule anyone has written. Eighty is unencrypted web, which is why redirecting it to the encrypted port is the first line of any server configuration. Four hundred and forty-three is the encrypted equivalent. A connection is not one state. It moves through a handshake, and a connection that fails partway leaves entries on both machines until they expire. A connection that is open in one direction and not the other is what a half-open firewall produces, and it fails as a timeout rather than a refusal. The difference between a refused connection and no response is the most useful diagnostic distinction available. Refused means nothing is listening on that port and the packet arrived. No response means it did not arrive, so the problem is upstream. Port scanning is a network probe and the authorisation question comes before the tool, not after. I also cover the two ports nobody has heard of that appear in every stack: the one a proxy listens on and the one a database is reached on internally, both of which are worth knowing before reading somebody's configuration.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →