G. COMMUNICATION PORTS AND NETWORK SECURITY
Communication ports are numerical identifiers (0 to 65,535) used by the TCP and UDP protocols to distinguish between different services on the same host.
Ports are divided into three categories by IANA:
Well-known ports: 0–1,023, reserved for standard services (HTTP, FTP, SSH, etc.).
Registered ports: 1,024–49,151, used by specific applications.
Dynamic/private ports (Ephemeral Ports): 49 152–65 535, used for outbound connections.
1. Main TCP ports (WAN → LAN)
|
TCP port |
Service |
Description |
|
20 / 21 |
FTP (File Transfer Protocol) |
File transfer (data / control) |
|
22 |
SSH (Secure Shell) |
Secure remote access, tunnelling, SFTP |
|
23 |
Telnet |
Unencrypted remote access — ⚠ obsolete, replaced by SSH |
|
25 |
SMTP |
Sending emails (outgoing server) |
|
53 |
DNS |
Domain name resolution (also UDP 53) |
|
67 / 68 |
DHCP |
Automatic IP address allocation |
|
80 |
HTTP |
Unsecured web browsing |
|
110 |
POP3 |
Receiving emails (download) |
|
119 |
NNTP |
Newsgroups (obsolete for most purposes) |
|
143 / 220 |
IMAP 3 / IMAP 4 |
Email access with server synchronisation |
|
443 |
HTTPS |
Encrypted web browsing (TLS) |
|
445 |
SMB/CIFS |
Windows file sharing (NetBIOS over IP) |
|
465 / 587 |
SMTPS / SMTP Submission |
Sending encrypted emails (SSL/STARTTLS) |
|
993 / 995 |
IMAPS / POP3S |
Encrypted incoming mail |
|
3389 |
RDP |
Windows Remote Desktop |
|
8080 |
HTTP alternative / Proxy |
Alternative HTTP port, web proxy |
2. Main UDP ports
|
UDP port |
Service |
Description |
|
53 |
DNS |
DNS queries (name resolution — and TCP for zone transfers) |
|
67 / 68 |
DHCP |
Automatic IP address allocation |
|
69 |
TFTP |
Simplified file transfer (firmware, configuration) |
|
123 |
NTP |
Network time synchronisation |
|
161 / 162 |
SNMP |
Network monitoring (requests / traps) |
|
500 / 4500 |
IKE / IKEv2 |
Key exchange for IPsec/VPN |
|
1194 |
OpenVPN |
Open-source VPN (including TCP) |
ℹ NetBIOS — ports à sécuriser
The UDP/TCP ports 137 (NetBIOS Name Service), 138 (NetBIOS Datagram) and 139 (NetBIOS Session) are used for Windows resource sharing. These ports must never be exposed to the internet: they would allow attackers to enumerate shared resources and users, and to establish unauthorised sessions. Internally, SMB 445 has replaced NetBIOS 139 since Windows 2000.
3. Virtual Private Networks (VPNs)
A VPN (Virtual Private Network) enables the establishment of a secure, encrypted communication tunnel between two geographically distant points via a public network (the Internet). The VPN tunnel ensures the confidentiality (encryption), integrity (HMAC) and authentication of data.
The VPN will assign a local network address to a PC connected via the internet. The PC is then automatically integrated into the network as if it were physically present. Encryption prevents any form of interception of data in transit.
a) VPN protocols
IPsec (IP Security): a suite of cryptographic protocols operating at Layer 3. Two modes: transport (encrypts only the payload) and tunnel (encrypts the entire original IP packet, encapsulated within a new packet). Used for site-to-site VPNs and remote access. Associated protocols: IKE/IKEv2 for key exchange.
SSL/TLS VPN (HTTPS VPN): uses the TLS protocol operating at Layer 7. Requires only a browser or a thin client. Easier to deploy than IPsec (bypasses NAT firewalls). Examples: Cisco AnyConnect, OpenVPN, WireGuard (modern protocol using ChaCha20/Poly1305).
L2TP/IPsec: L2TP (Layer 2 Tunneling Protocol) encapsulates PPP connections within an IP tunnel, combined with IPsec for encryption. Native support in Windows, macOS, iOS and Android.
PPTP: a proprietary Microsoft protocol using RC4 encryption, which is considered weak. Obsolete and not recommended.
WireGuard: a modern VPN protocol (2019), very simple(< 4,000 lines of code), uses modern cryptographic algorithms (ChaCha20, Poly1305, Curve25519, BLAKE2). Performance superior to IPsec and OpenVPN. Integrated into the Linux kernel since version 5.6.
b) Types of VPN
Site-to-site VPN (LAN-to-LAN): permanently connects two fixed networks. Replaces costly leased lines. Deployed on routers or firewalls at both ends.
Remote Access VPN: enables a mobile user to connect to the company network via the internet. VPN client software installed on a PC or smartphone.
MPLS VPN (provider): the VPN service is provided by the provider at the MPLS network level. The customer does not manage the encryption (trust in the provider). Equivalent to traditional leased lines but sharing the MPLS infrastructure.
SSL VPN (clientless): accessible via a standard web browser, with no client software required. Limited to web applications and published applications.
c) Components of a remote VPN connection
· VPN client software on the remote machine (native OS client or dedicated software).
· VPN equipment (access point, firewall with VPN functionality) on the corporate network side.
· A static public IP address (or a DDNS service) to connect to the VPN from the internet.
⚡ VPN et architecture Zero Trust
Zero Trust architecture (ZTNA — Zero Trust Network Access) goes beyond traditional VPNs: rather than granting full network access once connected, ZTNA applies granular access policies to each application or resource, with continuous verification of the device’s identity and security posture. SASE (Secure Access Service Edge) solutions combine SD-WAN and ZTNA into a unified cloud service (Zscaler, Cloudflare Access, Palo Alto Prisma).