Ports and protocols

Port fundamentals

A port is a logical opening identifying a service on a host, 0-65535. Well-known ports are 0-1023 and registered 1024-49151 (both IANA-registered); ephemeral ports are 49152-65535, temporary client-side ports with no registration.

The flow: the client’s ephemeral port talks to the server’s well-known port, and the server replies from its well-known port back to the ephemeral one. Ephemeral ports close after the task, and a new one gets picked next time.

TCP, UDP, ICMP

TCP is the reliable transport: the three-way handshake (SYN, SYN-ACK, ACK), sequence numbers plus acks for error recovery, windowing for flow control, and a 20-60 byte header.

UDP is connectionless “fire and forget” datagrams: an 8-byte header, no acks or retransmission. For speed-first traffic: live streams, gaming, VoIP, DNS lookups. Error handling falls to the application.

ICMP is network-layer diagnostics, not data transport. Ping tests reachability and latency, and ICMP messages report unreachable hosts, expired TTLs, router buffer issues. It’s abused by ICMP floods (DoS/DDoS) and the legacy Ping of Death, so some admins block it, at the cost of harder troubleshooting.

The port table

Overlaps with my CCNA ports note; this is the N10-009 set.

Choosing protocols

HTTPS displaced HTTP as the browsing default (encryption, user trust, better search ranking). SMTP and SMTPS send mail; POP3 and IMAP receive it, with IMAP managing mail on the server across devices.

SSH for secure command-line management, RDP for graphical Windows access, Telnet never. SMB stays inside the LAN.