Return to index.
Note that earliest assignments are exclusively 'odd' numbers because they're inherited from ARPANET NCP socket assignments, where sockets provided simplex connections – by convention, 'odd'-numbered sockets were for server-to-client data, while the corresponding 'even' sockets were used for client-to-server traffic – therefore each 'odd' assignment implicitly reserved the next higher 'even' socket as well. Explicit 'even' port assignments in the two-digit range tend to be much newer, well after the TCP/IP switchover.
A simple multiplexing protocol for accessing different services by name, instead of by port number. The client sends an ASCII protocol name, the server connects it to the desired service. Seen implemented by some inetd versions. (Inetd already operates by connecting the TCP socket to the spawned service handler's stdin/stdout, so this feature can be easily added without requiring proxying.)
Defined in RFC 1078 (1988), deprecated in RFC 7805.
| *connect* | |
| C: | SMTP |
| S: | + |
| S: | 220 hades.arpa ESMTP Postfix |
Before that, NCP socket 1 had been in use for the "Old Telnet" protocol (RFC 318, NIC 9348) until removal in RFC 870.
Originally, NCP socket 3 was assigned by RFC 349 (1972) (removed in RFC 870) to the original "File Transfer" protocol as defined in RFC 354 and RFC 385 (later the document reference changed to the same NIC 7014 as Telnet and RJE). RFC 739 calls it "Old File Transfer" and assigns socket 21 for "New File Transfer" (which is the text-based FTP known until today).
A protocol for submitting "punched card" batch jobs via TELNET.
Proposed in RFC 360 (1972), then RFC 407 (1972). Later the socket assignment in RFC 503 lists NIC 7014 as the protocol definition.
Probably the first protocol to use the numbered responses style now known from FTP/SMTP/HTTP. As with several other protocols from that era, RJE is at least in part designed to work with an interactive TELNET client.
| *connect* | |
| S: | 300 RJE server ready |
| S: | 000 Message of the day goes here |
| C: | USER=roundabout |
| S: | 330 Enter password |
| C: | PASS=aabbcc |
| S: | 230 Log-on completed |
| C: | OUT=:E/.sysprinter |
| S: | 200 Last command received ok |
| C: | OUT puncher = (S)HOSTB:NE/my.savepunch |
| S: | 200 Last command received ok |
| C: | INPUT=HOSTB:E/my.jobinput |
| S: | 240 File transfer has started |
| S: | 260 Job FOO123 accepted for processing |
According to "ARPANET History", the RJE protocol came too late and remained mostly unused, its place already taken by UCLA's interim NETRJS protocol (see below).
Echoes everything it receives.
Originally suggested in RFC 347, first implemented in RFC 361 for NCP, then defined in RFC 862 as a "debugging and measurement tool" for the early ARPA Internet.
Ignores everything it receives.
Originally suggested in RFC 348, first implemented in RFC 361 for NCP, defined in RFC 863 as a "debugging and measurement tool" for the early ARPA Internet.
Sometimes still used as a "harmless" destination for things such as Wake-on-LAN UDP messages.
Responds with a list of currently logged-in users in ASCII, with the output generally expected to come from commands such as 'who' on Unix or 'SYSTAT' on TENEX (hence the IANA name for this port).
Originally mentioned in RFC 503 for NCP as "Systat or who-is-on function", together with netstat.
Later defined in RFC 866 as a "debugging and measurement tool" for the early ARPA Internet deployment. Generally superseded by Finger.
Responds with the current time in arbitrary human-readable ASCII format (possibly the output of 'date' on Unix, or similar). See also time.
Originally mentioned in RFC 503 for NCP as "Date-Time function". Later defined in RFC 867 as a "debugging and measurement tool" for the early ARPA Internet deployment. NIST still operates Daytime service at time.nist.gov, alongside Time and NTP.
Originally mentioned in RFC 503 for NCP as "Netstat or who-is-up function", together with systat. Later mentioned in RFC 870 "Assigned numbers" but without any document reference.
(Likely to have been the 'netstat' command equivalent to systat (port 11), i.e. responding with an ASCII list of currently active TCP sockets, though the assignment name implies it might actually have been a list of hosts attached to the network.)
Responds with some random quote or another message in ASCII.
Originally mentioned in RFC 433 as unofficial "Oneliners" implemented by two BBN-TENEX hosts, then in RFC 739 as an official "Short Text Message" assignment. Later defined in RFC 865 as a "debugging and measurement tool" for the early ARPA Internet deployment.
Defined in 1990 by RFC 1159 (thus post-ARPANET), was a protocol to send text messages like using the Unix write command but between hosts.
Generates an infinite stream of ASCII characters.
Originally mentioned in RFC 361 alongside echo/discard for NCP, later in RFC 429; later defined in RFC 864 as a "debugging and measurement tool" for the early ARPA Internet deployment.
Assigned in RFC 820 for "File Transfer (Default Data)" as defined in RFC 765, accompanying "FTP (Control)" on port 21.
This is the server-side port (i.e. source port) used by FTP servers when establishing data connections to the client, in what's now called the "active" mode. A relic of the NCP era.
The original ARPANET protocol suite did not have duplex connections as standard, the way TCP does, nor even the ability to juggle several connections to the same port number (although this might have been an implementation limitation). Programs such as Telnet, upon connecting to the well-known port, used a separate "Initial Connection Protocol" (ICP) to negotiate a bidirectional link consisting of two simplex sockets on ephemeral ports. Because of that architecture it seems to have been natural for FTP to simply pick additional simplex sockets for data transfers.
Assigned in RFC 739 to the "New File Transfer Protocol".
Original ARPANET (NCP-based) drafts:
The oldest ARPANET protocol ever.
The original Telnet or "Logger" protocol was assigned socket 1 for NCP/ICP (RFC 349) and defined in RFC 318, with RFC 739 updating socket 1 to be "Old Telnet" and assigning socket 23 to "New Telnet".
Assigned in RFC 790 to the same SMTP as used today, originally defined in RFC 788.
Before that, NCP socket 25 was briefly (RFC 739; removed in RFC 776) assigned to a "Distributed Programming System" (see socket 33).
NCP: Socket 27 was assigned in RFC 739 to "NSW User System w/COMPASS FE", with the following document references:
See also socket 39, which was briefly assigned in RFC 750 to "NSW User System w/SRI FE". Later that was rescinded, and RFC 820 listed only port 27 (the COMPASS variant) as "NSW User System FE".
NCP sockets 29 and 31 were assigned in RFC 739 with a reference to:
Assigned in RFC 960 to a "Display Support Protocol" by Mike Corrigan at DDN, without a protocol reference.
Before that, NCP socket 33 had been briefly (RFC 739, removed in RFC 790) assigned to "DPS ICP" in reference to "Distributed Programming System", referencing RFC 707 and RFC 708:
A general placeholder assignment for site-specific network printing protocols.
Originally, NCP socket 35 was mentioned in RFC 739 for "IO Station Spooler" (no document reference).
Responds with the current time as a 32-bit binary value (offset from 1900-01-01 00:00:00), sharing the same epoch and "year 2036" rollover problem with NTPv3.
Originally assigned in RFC 739 and defined in RFC 738/NIC 42218 (1977) as "the Time Server protocol currently implemented on ITS hosts". Later updated in RFC 868 as a general standard ARPANET protocol. Still occassionally used as a simpler alternative to NTP (NIST still provides Time and Daytime service at time.nist.gov).
Assigned in RFC 900 to a "Resource Location Protocol" as defined in RFC 887:
Before that, NCP socket 39 was assigned in RFC 750 (removed in RFC 776) to "NSW User System w/SRI FE", sharing a reference with socket 27.
Originally assigned in RFC 739 and RFC 750 (the former missing the actual assignment) with a reference to:
First assigned in RFC 758 (the first TCP/IP-era "Assigned Numbers" document, thus also the first 'even' port number) with a reference to IEN-116:
First assigned in RFC 758 without a reference. Defined in RFC 812 specifically for interacting with the (then ARPANET-wide) DDN WHOIS database at the SRI-NIC machine, hence the official name 'NICNAME'. Still used today with the whois command to query various routing and domain registries, although slowly being superseded by the HTTP-based RDAP.
One-shot query/response protocol (client sends one line consisting of a query; server responds with arbitrary text).
| *connect* | |
| C: | AS206633 |
| S: | aut-num: AS206633 |
| S: | as-name: BROKEN-SYMLINK |
| S: | [...] |
RFC 870 assigns this to "MPM FLAGS Protocol", without a reference but most likely related to the Message Processing Module on ports 45-46.
NCP socket 45 and/or TCP port 45 were assigned in RFC 758 to "Internet Message Processing Module", referencing:
With RFC 820, port 45 was adjusted to "MPM (receive)" with port 46 added as a "send" port.
RFC 820 assigns TCP port 46 to "MPM (default send)", as companion to MPM port 45.
Assigned in RFC 762 for "NI FTP":
Later, this became the JANET "Blue Book" protocol.
IANA removed this assignment on 2017-05-18.
A protocol used by TIPs and TACs (which were ARPANET's "login hosts") to centrally authenticate users, as well to authorize the ARPANET connections they make.
Originally assigned in RFC 870 as "Login Host Protocol" without a protocol reference, although it was apparently specified in "TAC Access Control System Protocols, Second Edition" (1985) [BBN Tech Memo CC-0045] which doesn't appear to be publicly available.
Eventually a variant was published as RFC 1492 several decades later (due to the protocol having been adopted by Cisco terminal servers).
Before that, RFC 762 had assigned port 49 to "RAND Network Graphics Conference" (removed in RFC 820):
Assigned in RFC 870 for a protocol defined in:
Before that, RFC 762 had assigned port 51 to "Simple Internet Mail" without a document reference, and RFC 790 briefly had it as "Message Generator Control" (referencing IEN 172), removed in the subsequent RFC 820.
Assigned in RFC 870 for the very same DNS as used today.
Before that, RFC 762 had briefly assigned port 53 to "AUTODIN II FTP":
Assigned in RFC 770 to "ISI Graphics Language":
RFC 870 had assigned this to "Any Private Terminal Access".
Cisco IOS makes a connection on port 57 when the tunnel command is used.
Before that, briefly assigned in RFC 770 (removed in RFC 820) to "Mail Transfer", a precursor to SMTP:
See also RFC 771 "Mail Transition Plan".
RFC 870 had assigned this to "Any Private File Service". See also RFC 1037.
Before that, briefly assigned in RFC 790 to "New MIT Host Status", then in RFC 820 to "Augment File Mover", both without a protocol specification.
RFC 820 had assigned it to "NIMAIL", related to NI FTP (port 47):
This was, I believe, the JANET "Blue Book" mail protocol.
IANA removed this assignment on 2017-05-18.
Before that, RFC 900 had assigned it to "VIA Systems - FTP".
RFC 943 assigns this to "TACACS-Database Service", with a reference to:
Before that, NCP socket 65 was briefly (in RFC 433; removed in RFC 820) assigned to "Speech Data Base @ ll-tx-2", with SUR 37 as the reference document. Later RFC 739 updates the reference to:
Ports 67–68 became assigned to the "Bootstrap Protocol" in RFC 960. This superseded RARP, and gradually evolved into what we now know as DHCP.
Before that, NCP socket 67 was assigned in RFC 433 (removed in RFC 900) to "Datacomputer @ CCA". Later RFC 739 provides a reference:
tftpNCP socket 69 was first mentioned in RFC 433 as "CPYNET" implemented by some hosts, later (RFC 503) getting an official assignment, without any protocol reference.
Eventually RFC 770 had a double assignment for "CPYNET" as well as "Trivial File Transfer" as defined in:
Another remote job entry protocol similar to RJE, used specifically at UCLA Campus Computing Network for submitting jobs to an IBM 360. According to "ARPANET History", NETRJS was first defined by UCLA as an interim protocol because the official RJE protocol hadn't been available yet.
Defined in RFC 88, later RFC 189, eventually formalized in RFC 360 (which originates the 3-digit status codes seen in FTP/SMTP/HTTP), then RFC 740 - at the time only for ARPANET ICP, not yet for TCP/IP. See also RFC 307, RFC 325 for usage examples.
Current IANA database (as of RFC 820) reserves four adjacent ports without much explanation, but the original NCP-era RFC 503 (first appearance) had specifically assigned socket 71 to be used for EBCDIC and socket 73 for ASCII, with the 'even' companion sockets 72 and 74 being implicitly reserved for duplex transmission as was standard for NCP.
RFC 870 had assigned this to "Any Private Dial-out Service".
Before that, NCP socket 75 was briefly (in RFC 503) assigned to "NETRJS [TTY]" alongside the EBCDIC and ASCII variants. Later RFC 755 updated socket 73 as "NETRJS (ASCII-68)" and socket 75 as "NETRJS (ASCII-63)".
Assigned in RFC 739 to "any private RJE server".
An ASCII protocol for querying online user information, allowing to query either a free-form list of all logged-in users (similar to 'systat' or Unix 'who'), or detailed information about a specific user (including their contact information, where they are logged in from, and the "plan" file).
Originally assigned in RFC 739 and defined in RFC 742 (which includes several output examples). Unlike e.g. SYSTAT (port 11), the Finger protocol was quite widespread among various operating systems until the 2000s; a Finger client is included with Windows to this day.
This site has a Finger service, as well as a web-based gateway.
Assigned in RFC 820 without much explanation.
"An interesting story. The name attached to this port in the IANA list, Earl Killian, says he shouldn't be. He says "I don't know what 81 is, or whether it is still in use." Since Mr. Killian doesn't know what HOSTS2 is/was, and with Postel gone, I wonder if there's anyone left in the world who knows what 81 was/is for and who actually requested it."
Registered by Earl Killian <EAK@S1-C.ARPA>, <EAK@MORDOR.S1.GOV> of Lawrence Livermore National Labs. Removed by IANA on 2007-09-06.
Before that, NCP socket 81 was assigned to "Network BSYS" in RFC 739, again without any protocol reference.
"Another interesting story. The name attached to this port in the IANA list, Thomas M. Smith of Lockheed Martin, says "Sorry... there is no publicly available information regarding the details of the XFER Utility and its use of tcp and udp port #82. XFER employs a proprietary protocol which has not been disclosed."
RFC 750 listed NCP sockets 83 and 85 as "MIT ML Device" under the Host-Specific Functions category, without any specification reference (later a reference to David Moon as registrant was added).
RFC 770 assigned this to "any terminal link".
RFC 770 assigned this to "SU/MIT Telnet Gateway" under the Host-Specific Functions category; later RFC 776 added a reference to Mark Crispin at Stanford but no document specification.
RFC 776 assigned this to "MIT Dover Spooler" under the Host-Specific Functions category, with a reference to Eliot Moss at MIT but no specification document.
RFC 820 assigned this to "Device Control Protocol", with the only reference being Dan Tappan (BBN) as the registrant.
A remote logon protocol similar in purpose to Telnet, but used primarily by MIT ITS systems.
First mentioned in RFC 739 with a reference to:
Currently implemented by PuTTY.
RFC 923 assigns this to "Swift Remote Vitural File Protocol", with the only reference being Mark A. Rosenstein at MIT.
Before that, RFC 750 listed NCP socket 97 as "Datacomputer Status" under the Host-Specific Functions category, related to the "Datacomputer at CCA" socket 67. Eventually removed in RFC 900.
Assigned in RFC 960, with the only reference being Francine Perillo at SRI.
Most likely used by ARPANET TACs (aka TIPs) to retrieve news by calling telnet sri-nic tacnews when the @NEWS command was invoked.
Assigned in RFC 820 to "Metagram Relay", with only Geoff Goodfellow at SRI (Geoff@DARCOM-KA) as the registrant.
Assigned in RFC 820 to "NIC Host Name Server", referencing RFC 811:
This was an interim protocol for distributing HOSTS.TXT tables before the network switched to dynamic lookup protocols such as DNS.
Assigned in RFC 990.
RFC 820 had temporarily assigned this to "CSNET Mailbox Name Server (Telnet)", with the same reference as port 105; this was removed in RFC 870, leaving only the "Program" variant on port 105.
Later port 103 was assigned to "X.400" in RFC 990, together with "X.400 Send" on port 104.
RFC 2378 "The CCSO Nameserver (Ph) Architecture". Called so because it comes from the Computing and Communications Services Office (i.e. CCSO) of University of Illinois at Urbana-Champaign.
RFC 820 had originally assigned this to "CSNET Mailbox Name Server (Program)", referencing:
Assigned in RFC 820 to "Remote Telnet Service", with reference to RFC 818:
Assigned in RFC 900 for the first version of the POP protocol, becoming version 2 in RFC 943.
RFC 923 assigns this to "SUN Remote Procedure Call", and it's the same portmapper or rpcbind service that you might know from NFSv3 (although in earlier times it was used for a great many more protocols).
RFC 923 assigns this to an "Authentication Service" as defined in RFC 912.
This is more commonly known as the identd protocol, and is still encountered as part of IRC.
Assigned in RFC 943 to a "Simple File Transfer Protocol" that references:
Not to be confused with the now more common SFTP that is the "SSH File Transfer Protocol" (port 22), nor with FTPS.
Assigned in RFC 923 to the "UUCP Path Service" protocol defined in RFC 915:
Originally assigned in RFC 943 to a "USENET News Transfer Protocol".
Assigned in RFC 960 to:
Assigned in RFC 960 to the same NTP that is still widely in use:
Both assigned in RFC 960 to:
Assigned in RFC 990 to:
Assigned in RFC 990 without explanation.
Assigned in RFC 433 for "Survey Data [Kampe @ NMC]". Later RFC 739 updates the reference to:
At the time, it was in the "Experimental Functions" section, accompanied by a similar "NCP Measurement" socket 241 (RFC 388).
Assigned in RFC 433 to "LINK [Bressler @ BBN]". Later a reference added to: