Communication ports are numerical identifiers (0 to 65,535) used by the TCP and UDP protocols to distinguish between different services on the same host.

Ports are divided into three categories by IANA:

Well-known ports: 0–1,023, reserved for standard services (HTTP, FTP, SSH, etc.).

Registered ports: 1,024–49,151, used by specific applications.

Dynamic/private ports (Ephemeral Ports): 49 152–65 535, used for outbound connections.

1. Main TCP ports (WAN → LAN)

TCP port

Service

Description

20 / 21

FTP (File Transfer Protocol)

File transfer (data / control)

22

SSH (Secure Shell)

Secure remote access, tunnelling, SFTP

23

Telnet

Unencrypted remote access — ⚠ obsolete, replaced by SSH

25

SMTP

Sending emails (outgoing server)

53

DNS

Domain name resolution (also UDP 53)

67 / 68

DHCP

Automatic IP address allocation

80

HTTP

Unsecured web browsing

110

POP3

Receiving emails (download)

119

NNTP

Newsgroups (obsolete for most purposes)

143 / 220

IMAP 3 / IMAP 4

Email access with server synchronisation

443

HTTPS

Encrypted web browsing (TLS)

445

SMB/CIFS

Windows file sharing (NetBIOS over IP)

465 / 587

SMTPS / SMTP Submission

Sending encrypted emails (SSL/STARTTLS)

993 / 995

IMAPS / POP3S

Encrypted incoming mail

3389

RDP

Windows Remote Desktop

8080

HTTP alternative / Proxy

Alternative HTTP port, web proxy

2. Main UDP ports

UDP port

Service

Description

53

DNS

DNS queries (name resolution — and TCP for zone transfers)

67 / 68

DHCP

Automatic IP address allocation

69

TFTP

Simplified file transfer (firmware, configuration)

123

NTP

Network time synchronisation

161 / 162

SNMP

Network monitoring (requests / traps)

500 / 4500

IKE / IKEv2

Key exchange for IPsec/VPN

1194

OpenVPN

Open-source VPN (including TCP)

ℹ NetBIOS — ports à sécuriser

The UDP/TCP ports 137 (NetBIOS Name Service), 138 (NetBIOS Datagram) and 139 (NetBIOS Session) are used for Windows resource sharing. These ports must never be exposed to the internet: they would allow attackers to enumerate shared resources and users, and to establish unauthorised sessions. Internally, SMB 445 has replaced NetBIOS 139 since Windows 2000.

 

3. Virtual Private Networks (VPNs)

A VPN (Virtual Private Network) enables the establishment of a secure, encrypted communication tunnel between two geographically distant points via a public network (the Internet). The VPN tunnel ensures the confidentiality (encryption), integrity (HMAC) and authentication of data.

The VPN will assign a local network address to a PC connected via the internet. The PC is then automatically integrated into the network as if it were physically present. Encryption prevents any form of interception of data in transit.

a) VPN protocols

IPsec (IP Security): a suite of cryptographic protocols operating at Layer 3. Two modes: transport (encrypts only the payload) and tunnel (encrypts the entire original IP packet, encapsulated within a new packet). Used for site-to-site VPNs and remote access. Associated protocols: IKE/IKEv2 for key exchange.

SSL/TLS VPN (HTTPS VPN): uses the TLS protocol operating at Layer 7. Requires only a browser or a thin client. Easier to deploy than IPsec (bypasses NAT firewalls). Examples: Cisco AnyConnect, OpenVPN, WireGuard (modern protocol using ChaCha20/Poly1305).

L2TP/IPsec: L2TP (Layer 2 Tunneling Protocol) encapsulates PPP connections within an IP tunnel, combined with IPsec for encryption. Native support in Windows, macOS, iOS and Android.

PPTP: a proprietary Microsoft protocol using RC4 encryption, which is considered weak. Obsolete and not recommended.

WireGuard: a modern VPN protocol (2019), very simple(< 4,000 lines of code), uses modern cryptographic algorithms (ChaCha20, Poly1305, Curve25519, BLAKE2). Performance superior to IPsec and OpenVPN. Integrated into the Linux kernel since version 5.6.

b) Types of VPN

Site-to-site VPN (LAN-to-LAN): permanently connects two fixed networks. Replaces costly leased lines. Deployed on routers or firewalls at both ends.

Remote Access VPN: enables a mobile user to connect to the company network via the internet. VPN client software installed on a PC or smartphone.

MPLS VPN (provider): the VPN service is provided by the provider at the MPLS network level. The customer does not manage the encryption (trust in the provider). Equivalent to traditional leased lines but sharing the MPLS infrastructure.

SSL VPN (clientless): accessible via a standard web browser, with no client software required. Limited to web applications and published applications.

c) Components of a remote VPN connection

· VPN client software on the remote machine (native OS client or dedicated software).

· VPN equipment (access point, firewall with VPN functionality) on the corporate network side.

· A static public IP address (or a DDNS service) to connect to the VPN from the internet.

⚡ VPN et architecture Zero Trust

Zero Trust architecture (ZTNA — Zero Trust Network Access) goes beyond traditional VPNs: rather than granting full network access once connected, ZTNA applies granular access policies to each application or resource, with continuous verification of the device’s identity and security posture. SASE (Secure Access Service Edge) solutions combine SD-WAN and ZTNA into a unified cloud service (Zscaler, Cloudflare Access, Palo Alto Prisma).

Modifié le: vendredi 9 octobre 2026, 09:50