What does a port number mean? Who set the numbers 3389, 5005, and 8080? Understand port mapping and port conflicts all at once

clarify first: IP goes to the floor, port goes to the room
a piece of data must be sent online to the local authorities, and the address is written in two paragraphs. The first part is the IP address, responsible for locating the machine; The latter part is the port number, which is responsible for locating the specific program on the machine. To use a residential community analogy: IP is the building number, and the port is the room number. If the delivery slip only says 'Building 3,' it won't be delivered to anyone; you have to add a room number at the end.
Why do we need such a layer? If your phone is connected to WiFi, WeChat, Bilibili, and games are all online at the same time, and data from all three lines flows to the same IP. If there were no ports, and the data reached the phone's door, no one knew whether the package should be for WeChat or for games. So every networked program gets one or more port numbers from the system before starting work, which is like hanging a mailbox in the building. The packet header reads "Mailbox 5005 sent to 31.10," and the system sorts accordingly, accepting each other's letters without visiting each other's doors.
port number is a 16-bit number, so the range is from 0 to 65535, totaling over 65,000 numbers—enough for one machine. On your home computer, type netstat -ano. The number after the colon in the local address column is the port, and you can see dozens of entries working simultaneously. The full identity of a connection consists of five elements: 'source IP + source port + destination IP + destination port + protocol.' I mentioned the difference between TCP and UDP in the article this article specifically explains the port slot.
65535 accounts are ranked in different tiers
these sixty thousand accounts aren't just random catches. There's an international organization that manages the registry in three tiers, each with its own rules:
| gear | range | who is using | example |
| well-known ports | 0 - 1023 | the veteran standard for writing to the standard: dedicated system service | web pages 80, encrypted web pages 443, SSH 22, DNS 53 |
| registration ports | 1024 - 49151 | registered with software vendors, the address left for their own software | Remote Desktop 3389, Synology 5000, MySQL 3306 |
| Dynamic Port | 49152 - 65535 | system casually grabs and gives you a reply address | a number you temporarily get when you scroll through videos |
The first two
servers are 'waiting at the door for someone to come'—the number is fixed, and people come to you by number. The third tier is the 'Proactive Outing' client port. You open a video, and the system randomly grabs an account from this file to use as a reply email. After using it, you return it and switch to another one next time. So when you see the phone's connection in the router device list, the local port keeps changing by five digits, that's normal, not because it's been blocked.
set up a service at home and choose a local account: avoid the first 1,024 or 1,024 accounts, and don't run into accounts registered by big apps, starting from 10,000 or higher. The first time I paired my home NAS with WebDAV, I casually entered an 8080, but ended up clashing with another tool. I'll explain this in detail when discussing conflict troubleshooting later.
the numbers I often deal with at home, I organized them into a sheet and put them in the weak current box
have been in this field for years, and there are quite a few port numbers scattered across various articles. I compiled the ones that really come into contact with household scenarios into a table, printed it out, and stuck it on the inside of the weak current box cover. When mapping, I didn't need to look through the article again:
| port number | protocol | when will you encounter | |
| 80 / 443 | web pages / Encrypted webpages | TCP | Jiakuan basically shut down these two, so don't expect them to open their doors to the public |
| 22 | SSH remote login | TCP | NAS SSH the default is this one, and it's also the most frequently scanned account |
| 53 | DNS domain name resolution | UDP is the main approach | changing DNS to enter 223.5.5.5 is the way to go |
| 3389 | Windows remote desktop | TCP | makes a difference, even the home computer is mapped to it |
| 5000 / 5005 | Synology backend / WebDAV | TCP | NAS WebDAV hours 5005 plaintext 5006 encrypted at the time of , don't remember the |
| 554 | camera RTSP stream | TCP/UDP | NAS add camera the address tail you manually enter is this one |
| 9 | the network wake-up magic pack | UDP | remotely boot forwarding this number, the default port of the mobile app needs to be changed further |
| 1900 / 5353 | Casting Discovery / LAN Device Discovery | UDP | Phone Can Find TV Thanks to These Two Broadcast Ports |
| 8080 | backup web interfaces | TCP | various management pages are loved and are also hotspots for conflict |
there's a detail in this chart worth mentioning: 1900 and 5353 rely on multicast to do the job. When searching for TVs or printers on your phone, the whole room is filled with broadcasts. When I wrote multicast article caught them, they had gone several megapixels. This is also why, after enabling AP isolation or switching VLAN, casting can't be found—you find this step is blocked at the door, and the rest of the process is completely interrupted.
8080 occupied? Three steps to catch the real culprit
port conflicts are the most frustrating pitfalls I've ever stepped into. Once, when I opened a local gadget, the log only had one sentence: 'Port occupied, program exited,' and it was gone. Who exactly took the share? It doesn't say. At times like this, you can solve the case in three steps:
Step
: Type netstat -ano |, command line findstr: 8080, replace 8080 with the account you have a conflict with. The last column in the output is the PID, the process number. Step two: Open Task Manager, switch to the "Details" section, find the PID column, click and sort by number. Matching the number will reveal which process it is. Step three: either right-click to close it, or change your tool to a new port. That time, I found out it was a download tool that hadn't been properly uninstalled the day before, occupying 8080, with the process name hanging there. I was puzzled for a long time—turns out it was always running in the background.
changing ports is usually easier than killing processes, especially since the other party is a service the system cannot live without. Choose a number according to the local rules mentioned earlier, with tens of thousands or more. Also, the same command on Linux is ss -tlnp, which is useful for troubleshooting Docker container port conflicts on NAS. I mentioned in Docker that the internal and external container ports have two paths, and when conflicting, consider this layer first.
The
TCP 443 and UDP 443 are two different doors
this is the most counterintuitive point: TCP and UDP each manage their own port tables. TCP Door 443 and UDP Door 443 are two different rooms in the same building that do not connect to each other. When you set up mapping in the port forwarding or Mercury or Tenda backends, the "protocol" dropdown to select TCP, UDP, or ALL is essentially deciding which door to open. Choosing ALL is not vague processing; it means TCP and UDP are combined into one rule.
can't connect after setup, besides checking public IPs and other major issues, first go back and check the protocol. Consoles are the most typical: PS5 multiplayer the official table is divided into two columns: TCP and UDP. TCP 1935 and UDP 3074 are two separate entries. If you only turn the TCP side, the UDP door stays closed, and the yellow light in the game remains yellow. The download tool for my NAS is the same. Most of BT tracking and node interconnection are in UDP, so only enabling TCP is like losing half a leg.
back to my cousin's full answer: why do external ports need to be filled with high-digit numbers like 13389? Online web crawlers have dictionaries, and common numbers like 22, 3389, 8080 are listed in the first tier, knocking on doors one by one. If you move the external port to above 13,000 yuan, the dictionary won't hit the mark, and the knocking will drop significantly. I forwarded the 22nd on NAS, and in half a month, there were thousands of explosive records. Later, I changed the high-end ports and the world became much cleaner. Moving the port is not a safe; the password should be 16 digits or 16 digits, and both locks must be installed together.
is it safer to keep all ports closed? Don't worry about household expenses—just focus on three areas
seeing this, some might start to panic: With so many doors open at home, isn't it dangerous? On the contrary. The NAT on the home router is naturally a gatekeeper who only gets in and doesn't get out. If you haven't mapped it proactively, no one outside can knock on any of your doors. The real focus is on three places where doors open:
| where | ||
| door opens | my method | |
| forwarding via my own configured port | backend forwarding rule list | all external ports must be high-position, passwords start at 16 bits |
| UPnP mapping is automatically enabled | router UPnP mapping list | check regularly, and delete entries you don't recognize |
| DMZ main unit | the DMZ settings page in the backend | basically avoid touching home use; if you do, remember to close it |
Before mapping the device,
here's another prerequisite: first bind the device a static IP. The address is set to IP + port, but after the device reboots, the IP drifts and the mapping goes to someone else's home. This was the root of my first useless setup. I've written about the mapping portals for both Mercury and Tengda for the Mercury version and Tengda version There are only four fields, just fill in the fields facing each other.
finish with a clear order: first remember the numbers you often use at home (the table with the weak current box attached). If there is a conflict, use netstat to press PID to recruit people, build your own service, pick the highest level above 10,000, verify the protocol for mapping, then check both internal and external ports, and finally, check the UPnP list every quarter. After hearing this, my cousin changed the external port to four digits after his birthday plus ten thousand more—fine, since the dictionary wouldn't hit the mark, it would barely count as graduation.
