A server port exposure audit checks whether essential services are reachable from the public internet. The goal is to keep only the access that users need, while placing administration and database services behind stronger restrictions such as a VPN, IP allowlisting, or firewall rules.
Review ports 22, 3389, 3306, 5432, 2083, and 2087 separately. An open port does not always mean that access is possible, but it does show that a service may be reachable and should have an intentional security policy.
Table of Contents
What each port is used for
| Port | Service | Default exposure pattern |
|---|---|---|
| 22 | SSH | Private or restricted to administration IPs |
| 3389 | RDP | Private or restricted to administration IPs |
| 3306 | MySQL or MariaDB database access | Private; public access should be exceptional |
| 5432 | PostgreSQL database access | Private; public access should be exceptional |
| 2083 | Secure control panel access | Restricted or protected by an access policy |
| 2087 | Secure administrative control panel access | Restricted to authorised administrators |
SSH provides direct command-line control over a hosting account and is commonly used for website management, troubleshooting, backups, and server administration. That level of access makes port 22 an administrative entry point, not a general public service. See mybox’s SSH command reference for the role of SSH in server administration.
Ports 3306 and 5432 provide access to database services. A database port should normally be reachable only by the application server, an internal network, or approved administration addresses. A website does not need its database port exposed to every internet user.
Ports 2083 and 2087 provide secure control panel access. A control panel can manage sensitive settings such as websites, domains, email accounts, databases, SSL certificates, backups, cron jobs, and SSH access. Because the panel can control many parts of a hosting environment, access should be limited to the people and networks that administer it. The mybox panel overview describes these administrative functions.
What acceptable exposure looks like
- SSH on port 22: Keep it private where possible. If administrators need remote access, allow only approved source IP addresses or require access through a VPN. Use key-based authentication instead of relying only on passwords.
- RDP on port 3389: Keep it off the public internet where possible. Place it behind a VPN or allow connections only from fixed administration IP addresses.
- Database ports 3306 and 5432: Allow connections only from the application host, internal network, VPN, or specific administration addresses. They should not be open to all internet sources for normal website operation.
- Control panel ports 2083 and 2087: Restrict access to authorised users and trusted networks. If public access is required, apply IP allowlisting or another access control layer and use strong authentication.
The correct exposure depends on how the service is used. A public port can be acceptable when it is required for a defined workflow and protected by a narrow source-IP rule. A port that has no business purpose should be closed rather than left available.
How to perform the audit
- List the server’s public addresses. Record every public IPv4 or IPv6 address that can receive connections. Include cloud instances, dedicated servers, and other systems used for administration or databases.
- Check each target port from outside the server. Test 22, 3389, 3306, 5432, 2083, and 2087 from a network that is not the server’s internal network. Record whether each port appears open, closed, or filtered.
- Identify the service behind an open port. Confirm that an open port belongs to the expected service. A port that is open without a known purpose requires review before it is kept accessible.
- Compare access with the intended users. For each open port, write down who needs access, from which network, and for what task. Administration ports should not be available to every internet address unless there is a clear operational reason.
- Review the firewall rule. Check whether the rule allows all sources or only approved addresses. Replace broad rules with source-specific rules where the service does not need public reachability.
- Choose the restriction. Close unused ports. For required administration access, use a VPN or IP allowlisting. For database access, allow only the application server or approved private networks.
- Harden SSH access. Use key-based authentication, remove access that is no longer needed, and keep SSH reachable only from the administration path where practical.
- Test after every change. Verify that approved administrators can still connect and that an unauthorised network can no longer reach the restricted port.
Remediation by risk level
Close the port when the service is unused or when administration can be performed through another approved path. Removing an unnecessary exposure reduces the number of services that must be protected.
Use a VPN when several administrators or systems need access without placing the service directly on the public internet. The VPN becomes the controlled entry point, while SSH, RDP, database, or panel access remains private.
Use IP allowlisting when administrators connect from fixed office, home, or management-network addresses. Permit only those addresses and review the list when an administrator’s network changes.
Use firewall rules to define which source addresses may reach each port. A separate rule for SSH, RDP, each database service, and each control panel port makes the audit easier to review and reduces accidental broad access.
When to repeat the audit
Repeat the audit after a firewall change, server migration, new remote-access requirement, or control panel change. Also review the port list when an application begins using a database from another host. The expected result is a short list of open ports with a named purpose, an approved source, and a clear owner.