Infrastructure ports support the network services that keep websites, servers, and business networks working. Ports 53, 67 and 68, 123, 389 and 636, and 161 and 162 are associated with DNS, DHCP, NTP, LDAP, and SNMP. Each service has a different role, and each port should be exposed only where it is needed.
The main distinction is between TCP and UDP. TCP creates a connection and provides ordered delivery. UDP sends individual datagrams without establishing a connection. The protocol and port combination determines how a service communicates and how network access should be controlled.
Table of Contents
Infrastructure port reference
| Port | Service | Transport | Typical purpose |
|---|---|---|---|
| 53 | DNS | UDP and TCP | Resolves domain names and supports DNS responses and transfers |
| 67 | DHCP server | UDP | Receives requests from DHCP clients |
| 68 | DHCP client | UDP | Receives address configuration from a DHCP server |
| 123 | NTP | UDP | Synchronises system clocks |
| 389 | LDAP | TCP, and sometimes UDP | Directory queries and directory communication |
| 636 | LDAPS | TCP | LDAP communication protected with TLS |
| 161 | SNMP | UDP | Monitoring queries sent to network devices |
| 162 | SNMP traps | UDP | Alerts sent from monitored devices to a monitoring system |
Common TCP and UDP port assignments are listed in network port references such as this TCP and UDP port reference and this network port reference.
What port 53 does: DNS
DNS translates a domain name into information such as the destination address used to reach a service. A client sends a DNS query to a resolver, and the resolver returns an answer that the client can use to connect.
DNS commonly uses UDP port 53 for regular queries because the exchange is small and does not need a persistent connection. TCP port 53 is also used when a response is too large for the UDP exchange or when DNS systems perform specific server-to-server operations. DNS security and availability matter because problems in DNS can affect how services are reached. Research has examined the effect of DNS insecurity on time and network behaviour in The Impact of DNS Insecurity on Time.
A public DNS server may legitimately accept queries from the internet when it is intended to provide public name resolution. A private resolver should normally accept queries only from approved networks. An open resolver can be abused, so access rules should match the resolver’s purpose.
What ports 67 and 68 do: DHCP
DHCP gives clients network settings such as an address and other configuration needed to communicate. The DHCP server listens on UDP port 67, while the client uses UDP port 68.
DHCP is normally used inside a local network. A client may not yet have an address when it starts, so the first exchange uses local network communication. DHCP traffic is usually restricted to the network where the clients and server operate. Routers or DHCP relay functions can pass requests between network segments when the design requires a central DHCP server.
A DHCP server exposed to untrusted networks can influence the configuration given to clients. DHCP security has been studied in Dark Deceptions in DHCP: Dismantling Network Defenses. Public internet access to DHCP ports is not a normal requirement for serving clients inside a private network.
What port 123 does: NTP
NTP synchronises the clocks of computers, servers, and network devices. It normally uses UDP port 123. Accurate time helps systems record events in the correct order and supports services that depend on consistent timestamps.
An organisation may allow outbound NTP requests from internal systems to an approved time source. A time server may also accept inbound NTP traffic from defined clients. The required access depends on whether the system is acting as a client, an internal time server, or a public time service. Port 123 should not be left broadly accessible when the service does not need public clients.
What ports 389 and 636 do: LDAP and LDAPS
LDAP is a protocol for communicating with a directory. A directory can store and provide information used by business systems, such as accounts, groups, and other directory entries. LDAP commonly uses TCP port 389.
LDAPS uses TCP port 636 and protects LDAP communication with TLS. This creates an important difference between the two ports: LDAP on port 389 does not by itself mean that the whole connection is encrypted, while LDAPS is the TLS-protected form. Port 389 may still be used in environments that apply encryption through a separate negotiated method, but the security setting must be deliberate.
Directory services are commonly restricted to applications, servers, or networks that need them. Public exposure can make a directory service reachable by unknown systems and increases the importance of strong access controls and encrypted communication.
What ports 161 and 162 do: SNMP
SNMP monitors and manages network devices. A monitoring system sends requests to a device on UDP port 161. The device can send an unsolicited notification, called a trap, to the monitoring system on UDP port 162.
Port 161 is normally allowed from approved monitoring systems to managed devices. Port 162 is normally allowed from managed devices to the monitoring system. These ports usually belong on a management network or a restricted path rather than on the public internet. Rules should separate monitoring traffic from general user traffic.
How the services work together
A typical client first uses DHCP to receive network configuration. It then uses DNS to find the address of a website, server, or directory service. The client may contact LDAP or LDAPS for directory-based identity and access. NTP keeps the client and servers aligned in time, while SNMP allows an approved monitoring system to observe devices and receive alerts.
These services are separate, but a problem in one can affect the others. Without DHCP, a new client may not receive usable network settings. Without DNS, users and applications may not find services by name. Incorrect system time can make event records harder to compare and can affect time-sensitive security processes. Without SNMP access, a monitoring system may not receive device data or traps.
When infrastructure ports should be open
Open a port only on the network path required by the service. Public exposure can be legitimate for a public DNS service or another intentionally public service. Internal DHCP, directory, time, and monitoring services usually need narrower access based on client, server, or management networks.
- Allow DNS access according to whether the server is a public resolver, an authoritative service, or an internal resolver.
- Keep DHCP access within the networks that contain the intended clients and DHCP infrastructure.
- Allow NTP only between approved clients and approved time sources.
- Prefer LDAPS or another deliberately protected LDAP configuration for directory communication that crosses an untrusted network.
- Allow SNMP requests and traps only between managed devices and approved monitoring systems.
Internet-facing services should be reviewed as part of the overall security design. Open service vulnerabilities can expose systems when a service is reachable without the controls appropriate to its role, as described by Rogers’ overview of open service vulnerabilities. The correct setting is not to open every standard port, but to permit the exact traffic required by each infrastructure service.