Wednesday, May 2, 2007

Well Known Ports

If you have even wondered what port tacacs runs on (in case you are in the middle of constructing an ACL and you don't have access to google). All you need to do is enter the following in the router:

!
router# show ip port-map

or:

!
router# show ip nbar port-map

Here is what you'll get with the port-map:

Default mapping: snmp udp port 161 system defined
Default mapping: echo tcp port 7 system defined
Default mapping: echo udp port 7 system defined
Default mapping: telnet tcp port 23 system defined
Default mapping: wins tcp port 1512 system defined
Default mapping: n2h2server tcp port 9285 system defined
Default mapping: n2h2server udp port 9285 system defined
Default mapping: nntp tcp port 119 system defined
Default mapping: pptp tcp port 1723 system defined
Default mapping: rtsp tcp port 554,8554 system defined
Default mapping: bootpc udp port 68 system defined
Default mapping: gdoi udp port 848 system defined
Default mapping: h323-nxg udp port 2099 system defined
Default mapping: h323-nxg tcp port 2099 system defined
Default mapping: tacacs udp port 49 system defined
Default mapping: gopher tcp port 70 system defined
Default mapping: icabrowser udp port 1604 system defined
Default mapping: skinny tcp port 2000 system defined
Default mapping: sunrpc tcp port 111 system defined
Default mapping: sunrpc udp port 111 system defined
Default mapping: biff udp port 512 system defined
Default mapping: router udp port 520 system defined
Default mapping: entrust-svc-hdlr tcp port 709,710 system defined
Default mapping: entrust-svc-hdlr udp port 709,710 system defined
Default mapping: ircs tcp port 994 system defined
Default mapping: orasrv tcp port 1525...1529 system defined
Default mapping: ms-cluster-net udp port 3343 system defined
Default mapping: kermit tcp port 1649 system defined
Default mapping: gnutella tcp port 6346...6349 system defined
Default mapping: gnutella tcp port 6355,5634 system defined
Default mapping: gnutella udp port 6346...6348 system defined
Default mapping: isakmp udp port 500 system defined
Default mapping: sshell tcp port 614 system defined
Default mapping: sshell udp port 614 system defined

• And here is what you get with the nbar option:

port-map bgp udp 179
port-map bgp tcp 179
port-map bittorrent tcp 6969 6881 6882 6883 6884 6885 6886 6887 6888 6889
port-map citrix udp 1604
port-map citrix tcp 2598 2512 2513 1494
port-map cuseeme udp 7648 7649 24032
port-map cuseeme tcp 7648 7649
port-map dhcp udp 67 68
port-map directconnect tcp 411 412 413
port-map dns udp 53
port-map dns tcp 53
port-map edonkey tcp 4662
port-map exchange tcp 135
port-map fasttrack tcp 1214
port-map finger tcp 79
port-map ftp tcp 21
port-map gnutella udp 6346 6347 6348
port-map gnutella tcp 6346 6347 6348 6349 6355 5634
port-map gopher udp 70
port-map gopher tcp 70
port-map h323 udp 1300 1718 1719 1720 11720
port-map h323 tcp 1300 1718 1719 1720 11000 - 11999
port-map http tcp 80
port-map imap udp 143 220
port-map imap tcp 143 220
port-map irc udp 194
port-map irc tcp 194
port-map kerberos udp 88 749
port-map kerberos tcp 88 749
port-map l2tp udp 1701
port-map ldap udp 389
port-map ldap tcp 389
port-map mgcp udp 2427 2727
port-map mgcp tcp 2427 2428 2727
port-map netbios udp 137 138
port-map netbios tcp 137 139
port-map netshow tcp 1755
port-map nfs udp 2049
port-map nfs tcp 2049
port-map nntp udp 119
port-map nntp tcp 119
port-map notes udp 1352
port-map notes tcp 1352
port-map novadigm udp 3460 3461 3462 3463 3464 3465
port-map novadigm tcp 3460 3461 3462 3463 3464 3465
port-map ntp udp 123
port-map ntp tcp 123
port-map pcanywhere udp 22 5632
port-map pcanywhere tcp 65301 5631
port-map pop3 udp 110
port-map pop3 tcp 110
port-map pptp tcp 1723
port-map printer udp 515
port-map printer tcp 515
port-map rcmd tcp 512 513 514
port-map rip udp 520
port-map rsvp udp 1698 1699
port-map rtsp tcp 554 8554
port-map secure-ftp tcp 990
port-map secure-http tcp 443
port-map secure-imap udp 585 993
port-map secure-imap tcp 585 993

and for those of you that are still reading.... tacacs runs on port 49.