{"id":14021,"date":"2026-09-21T08:54:49","date_gmt":"2026-09-21T06:54:49","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=14021"},"modified":"2026-09-21T08:54:54","modified_gmt":"2026-09-21T06:54:54","slug":"server-port-exposure-checklist-which-common-ports-should-be-reachable","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/","title":{"rendered":"Server Port Exposure Checklist: Which Common Ports Should Be Reachable?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A server port exposure checklist should confirm that each reachable port is needed by a known service and accessible only from the networks that require it. Each exposed port should have an identified owner, service, reason, and approved source network.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#How_to_review_an_exposed_port\" >How to review an exposed port<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#Public_web_ports\" >Public web ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#DNS_ports\" >DNS ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#Mail_transport_ports\" >Mail transport ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#SSH_access\" >SSH access<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#Database_ports\" >Database ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#Remote_desktop_access\" >Remote desktop access<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/server-port-exposure-checklist-which-common-ports-should-be-reachable\/#How_to_verify_changes_safely\" >How to verify changes safely<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_review_an_exposed_port\"><\/span>How to review an exposed port<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Review each reachable port as a service entry, not as an isolated number. Record the port number, the service using it, the server or system owner, the required source networks, and the reason access is needed.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>List the ports that are reachable from outside the server.<\/li>\n\n\n\n<li>Match each port to the service that should be listening.<\/li>\n\n\n\n<li>Confirm the owner and the business or technical reason for access.<\/li>\n\n\n\n<li>Record whether access must be public, limited to known networks, or available only locally.<\/li>\n\n\n\n<li>Remove or restrict entries that have no current owner or purpose.<\/li>\n\n\n\n<li>Verify the result from an approved network after every change.<\/li>\n<\/ol>\n\n\n\n<\/div>\n\n<div id=\"mybox-1302336124\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A port can be open for a valid reason and still be too widely accessible. The key decision is whether the service and its source networks match the documented need.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Public_web_ports\"><\/span>Public web ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Website access normally requires the ports assigned to the public web service to be reachable from the internet. Check that each reachable web port serves the intended website or application and that its owner is documented.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is the port required for a public website or application?<\/li>\n\n\n\n<li>Does the listening service match the website owner and server?<\/li>\n\n\n\n<li>Should the service be reachable by everyone, or only by a private network?<\/li>\n\n\n\n<li>Are unused web listeners removed or restricted?<\/li>\n\n\n\n<li>After a firewall change, does the website still respond from an approved external network?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Keep public access limited to the web services that visitors actually use. Do not expose an administrative interface through a public web port unless that access is explicitly required and documented.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNS_ports\"><\/span>DNS ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Review DNS access separately from website access. A server that provides DNS has a different exposure purpose from a server that only hosts website files.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is this server an intended DNS service?<\/li>\n\n\n\n<li>Is the port reachable from the networks that need to query or manage DNS?<\/li>\n\n\n\n<li>Is public access required, or should queries be limited to trusted networks?<\/li>\n\n\n\n<li>Who owns the DNS service and approves changes?<\/li>\n\n\n\n<li>Does the service stop responding when access is restricted as expected?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Document DNS ownership separately from domain ownership and web hosting ownership. This prevents a DNS port from remaining open simply because the same server also hosts a website.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Mail_transport_ports\"><\/span>Mail transport ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Mail transport access should be tied to a defined mail role. Check whether the server sends mail, receives mail, or performs both functions.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What mail function requires the port?<\/li>\n\n\n\n<li>Is the service intended to accept connections from the public internet?<\/li>\n\n\n\n<li>Which source networks are allowed to submit or relay mail?<\/li>\n\n\n\n<li>Who owns the mail service and reviews its access rules?<\/li>\n\n\n\n<li>Can unnecessary mail listeners be closed without affecting delivery?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Record separate rules for public delivery and trusted submission. They represent different access needs and should not be treated as one general mail exception.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SSH_access\"><\/span>SSH access<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SSH provides direct control of a hosting account through the command line. It is used for website management, troubleshooting, backups, and server administration, so its exposure should have a clear owner and source network. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/essential-ssh-commands-a-practical-cheat-sheet-for-server-administration\/\">mybox describes SSH access as direct command-line control of a hosting account<\/a>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is SSH required for current administration work?<\/li>\n\n\n\n<li>Which administrators or support networks need access?<\/li>\n\n\n\n<li>Can access be limited to a private network or approved addresses?<\/li>\n\n\n\n<li>Who approves SSH access and reviews it?<\/li>\n\n\n\n<li>After a restriction, can an approved administrator still connect?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not leave SSH reachable from broad networks without a documented reason. If FTP is used for file transfer, document it as a separate service. FTP transfers files between a client and server over a TCP-based connection and is commonly used to upload, download, and manage website files on a remote server. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/protocols-ftp\/\">See the mybox explanation of FTP<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Database_ports\"><\/span>Database ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Database access should be limited to the applications, administrators, or networks that require it. A database port does not need public access merely because the website using the database is public.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which application or administrator owns the connection?<\/li>\n\n\n\n<li>Does the database need access from the internet, or only from the application server?<\/li>\n\n\n\n<li>Are approved source networks recorded?<\/li>\n\n\n\n<li>Is the port still required after an application or migration change?<\/li>\n\n\n\n<li>Can the database remain reachable internally while public access is removed?<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Remote_desktop_access\"><\/span>Remote desktop access<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Remote desktop access should have an identified user group, owner, and source network. Check whether administrators need direct access from outside the private network or whether access can be limited to an approved management network.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which systems require remote desktop access?<\/li>\n\n\n\n<li>Who is responsible for approving and reviewing access?<\/li>\n\n\n\n<li>Are connections limited to the networks used by administrators?<\/li>\n\n\n\n<li>Is public reachability still required?<\/li>\n\n\n\n<li>Can an approved user connect after the firewall change?<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_verify_changes_safely\"><\/span>How to verify changes safely<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Make one access change at a time and keep the previous rule available for rollback. Test each service from the network that should be allowed and, where appropriate, from a network that should be denied.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm that the intended service is reachable.<\/li>\n\n\n\n<li>Confirm that an unapproved source cannot reach the service.<\/li>\n\n\n\n<li>Check that the service owner can complete the required task.<\/li>\n\n\n\n<li>Record the date, change, owner, source networks, and test result.<\/li>\n\n\n\n<li>Remove temporary access when the approved task is complete.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A complete port review leaves every reachable service with a clear purpose, an owner, an approved source network, and a recorded verification result. Public web access may need broad reachability, while DNS, mail, SSH, databases, and remote desktop access should each be reviewed according to their specific role.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[],"class_list":["post-14021","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14021\/revisions"}],"predecessor-version":[{"id":14024,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14021\/revisions\/14024"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=14021"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=14021"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=14021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}