Quick reference for network security — ports, protocols, firewall rules, TLS config, and defensive commands.
TCP/IPFirewallsTLSVPN
Common Ports
| Port |
Service |
Port |
Service |
| 21 | FTP | 143 | IMAP |
| 22 | SSH | 443 | HTTPS |
| 25 | SMTP | 445 | SMB |
| 53 | DNS | 3306 | MySQL |
| 80 | HTTP | 3389 | RDP |
| 123 | NTP | 5432 | PostgreSQL |
Protocol Quick Reference
| Protocol |
Layer |
Notes |
| TCP | Transport | Reliable, connection-oriented |
| UDP | Transport | Fast, no delivery guarantee |
| ICMP | Network | ping, traceroute |
| ARP | Link | IP-to-MAC, no auth |
| DNS | Application | Use DNSSEC + DoH |
Nmap Flags (Lab Use)
| Flag |
Purpose |
| -sS | SYN scan (requires root) |
| -sV | Service/version detection |
| -O | OS fingerprinting |
| -p- | All 65535 ports |
| -A | Aggressive (OS, version, scripts) |
| -sC | Default NSE scripts |
| -T4 | Faster timing template |
# Authorized target only
nmap -sV -sC -T4 scanme.nmap.org
Firewall Rules
nftables
nft add table inet filter
nft add chain inet filter input { type filter hook input priority 0 \; policy drop \; }
nft add rule inet filter input ct state established,related accept
nft add rule inet filter input tcp dport {22,443} accept
nft list ruleset
iptables (legacy)
iptables -P INPUT DROP
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -L -n -v
tcpdump / Wireshark Filters
| Tool |
Filter |
Matches |
| tcpdump | tcp port 443 | HTTPS traffic |
| tcpdump | host 10.0.0.5 | One host |
| tcpdump | 'tcp[13]&2!=0' | SYN packets |
| Wireshark | tcp.flags.syn==1 | SYN packets |
| Wireshark | http.request | HTTP requests |
| Wireshark | dns | DNS traffic |
tcpdump -i eth0 -nn -c 100 'tcp port 443'
tcpdump -i eth0 -w capture.pcap host 10.0.0.5
TLS / Cipher Config
# nginx: TLS 1.2/1.3 only, strong ciphers, HSTS
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
add_header Strict-Transport-Security "max-age=63072000" always;
# Test a server's TLS config
openssl s_client -connect example.com:443 -tls1_3
Subnetting / CIDR
| CIDR |
Netmask |
Hosts |
| /24 | 255.255.255.0 | 254 |
| /25 | 255.255.255.128 | 126 |
| /26 | 255.255.255.192 | 62 |
| /27 | 255.255.255.224 | 30 |
| /30 | 255.255.255.252 | 2 |