1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,450
we're going to discuss ports and protocols.

3
00:00:03,450 --> 00:00:05,550
In security, one of the most important things

4
00:00:05,550 --> 00:00:07,260
is for you to ensure that you understand

5
00:00:07,260 --> 00:00:09,180
what openings you've created inside

6
00:00:09,180 --> 00:00:10,710
of your computer systems.

7
00:00:10,710 --> 00:00:12,570
When it comes to computers and networks,

8
00:00:12,570 --> 00:00:14,340
most of these openings are going to be created

9
00:00:14,340 --> 00:00:16,740
using the concept of an open port.

10
00:00:16,740 --> 00:00:19,500
Now, a port is simply a logical communication endpoint

11
00:00:19,500 --> 00:00:21,690
that exists on your computer or server.

12
00:00:21,690 --> 00:00:23,460
For example, if you're running a secure

13
00:00:23,460 --> 00:00:24,990
web server that's used for e-commerce

14
00:00:24,990 --> 00:00:27,465
on your system, you're going to have port 443 open

15
00:00:27,465 --> 00:00:29,580
and listening for any inbound requests

16
00:00:29,580 --> 00:00:31,410
from your potential visitors.

17
00:00:31,410 --> 00:00:32,850
Now, ports are going to be classified

18
00:00:32,850 --> 00:00:35,130
as either inbound or outbound ports.

19
00:00:35,130 --> 00:00:37,170
An inbound port is used when a computer

20
00:00:37,170 --> 00:00:39,360
or server is listening for a connection.

21
00:00:39,360 --> 00:00:40,950
Just as in my earlier example,

22
00:00:40,950 --> 00:00:43,380
our web server had port 443 open

23
00:00:43,380 --> 00:00:44,970
and listening for a connection.

24
00:00:44,970 --> 00:00:46,500
That is an inbound port.

25
00:00:46,500 --> 00:00:48,060
It's just sitting there and waiting for somebody

26
00:00:48,060 --> 00:00:49,980
to come along and connect to it.

27
00:00:49,980 --> 00:00:51,660
Now, an outbound port on the other hand,

28
00:00:51,660 --> 00:00:53,850
is going to be open by a computer whenever it wants

29
00:00:53,850 --> 00:00:55,530
to connect to a given server.

30
00:00:55,530 --> 00:00:57,390
If my computer is attempting to make a connection

31
00:00:57,390 --> 00:01:00,120
to your web server over port 443,

32
00:01:00,120 --> 00:01:01,650
then my computer is actually going to open

33
00:01:01,650 --> 00:01:03,240
up a random high number port,

34
00:01:03,240 --> 00:01:05,519
like port 52363,

35
00:01:05,519 --> 00:01:07,380
and then it's going to make an outbound request

36
00:01:07,380 --> 00:01:11,100
to your web server using your port 443.

37
00:01:11,100 --> 00:01:12,360
Now, what does all this look like

38
00:01:12,360 --> 00:01:13,590
out in the real world?

39
00:01:13,590 --> 00:01:15,630
Well, let's say we have an example of an inbound

40
00:01:15,630 --> 00:01:17,280
and outbound port that's going to be used

41
00:01:17,280 --> 00:01:19,619
when my laptop attempts to connect

42
00:01:19,619 --> 00:01:21,000
to a remote server over SSH,

43
00:01:21,000 --> 00:01:23,250
which is the Secure Shell protocol.

44
00:01:23,250 --> 00:01:24,690
Now first we're going to have a server

45
00:01:24,690 --> 00:01:26,760
that has a public IP address assigned to it

46
00:01:26,760 --> 00:01:28,590
that's listening on port 22.

47
00:01:28,590 --> 00:01:31,260
So port 22 is going to be our inbound port

48
00:01:31,260 --> 00:01:32,970
awaiting a new connection.

49
00:01:32,970 --> 00:01:35,040
In this case, port 22 will be open

50
00:01:35,040 --> 00:01:37,080
awaiting for that connection to occur.

51
00:01:37,080 --> 00:01:38,670
Now I also have my laptop

52
00:01:38,670 --> 00:01:39,503
and it's the one that wants

53
00:01:39,503 --> 00:01:40,980
to make that connection.

54
00:01:40,980 --> 00:01:42,180
My laptop is going to

55
00:01:42,180 --> 00:01:43,800
be assigned a private IP address

56
00:01:43,800 --> 00:01:46,350
because my network is using network address translation

57
00:01:46,350 --> 00:01:47,820
at the router, and this gives me

58
00:01:47,820 --> 00:01:50,100
additional protections inside of my network.

59
00:01:50,100 --> 00:01:51,300
Now notice at this point,

60
00:01:51,300 --> 00:01:53,880
my laptop doesn't have any ports open yet,

61
00:01:53,880 --> 00:01:56,280
so now my laptop wants to go and establish

62
00:01:56,280 --> 00:01:57,870
that SSH connection.

63
00:01:57,870 --> 00:01:59,100
To do that, it's going to open

64
00:01:59,100 --> 00:02:01,170
up an outbound port on itself and assign

65
00:02:01,170 --> 00:02:02,850
some high number random port to it,

66
00:02:02,850 --> 00:02:05,550
like 51233, and then it's going to

67
00:02:05,550 --> 00:02:07,680
send a request to the SSH server

68
00:02:07,680 --> 00:02:09,900
that is listening over port 22,

69
00:02:09,900 --> 00:02:11,550
which is the server's inbound port,

70
00:02:11,550 --> 00:02:13,920
and it's going to be destined for its IP address,

71
00:02:13,920 --> 00:02:14,753
which in this case

72
00:02:14,753 --> 00:02:19,530
is going to be assigned as 46.124.6313.

73
00:02:19,530 --> 00:02:21,510
Now once the server receives this request

74
00:02:21,510 --> 00:02:23,910
on port 22, it has to respond to it.

75
00:02:23,910 --> 00:02:26,220
So it's going to send a packet of information back

76
00:02:26,220 --> 00:02:29,010
to my laptop's IP using the outbound port

77
00:02:29,010 --> 00:02:31,020
that was opened originally, in this case,

78
00:02:31,020 --> 00:02:33,960
that was port 51233, in reality,

79
00:02:33,960 --> 00:02:36,060
it's going to be a public facing IP address

80
00:02:36,060 --> 00:02:37,020
of my router.

81
00:02:37,020 --> 00:02:38,610
But for our example here on the screen,

82
00:02:38,610 --> 00:02:40,590
I'm just going to use the private IP address

83
00:02:40,590 --> 00:02:45,590
of 192.168.145 just to keep our example clear.

84
00:02:45,780 --> 00:02:47,820
So at this point, my laptop has gone out

85
00:02:47,820 --> 00:02:49,230
and made the request to the server

86
00:02:49,230 --> 00:02:51,030
and the server has answered that request.

87
00:02:51,030 --> 00:02:52,560
This now establishes a session

88
00:02:52,560 --> 00:02:54,090
between both of these devices

89
00:02:54,090 --> 00:02:55,020
and we can then communicate

90
00:02:55,020 --> 00:02:56,490
back and forth as needed.

91
00:02:56,490 --> 00:02:57,717
Once that session is over,

92
00:02:57,717 --> 00:02:59,370
the connection is going to be closed,

93
00:02:59,370 --> 00:03:01,200
my laptop will close its outbound port

94
00:03:01,200 --> 00:03:02,580
because it's no longer needed,

95
00:03:02,580 --> 00:03:04,920
and the server will keep open its inbound port

96
00:03:04,920 --> 00:03:06,810
so they can receive requests from the next user

97
00:03:06,810 --> 00:03:08,490
who wants to be able to use it.

98
00:03:08,490 --> 00:03:09,930
So now that we understand a little bit

99
00:03:09,930 --> 00:03:11,790
about how ports work in the real world,

100
00:03:11,790 --> 00:03:12,780
let's talk a little bit more

101
00:03:12,780 --> 00:03:14,520
about the ports themself.

102
00:03:14,520 --> 00:03:15,900
In addition to being classified

103
00:03:15,900 --> 00:03:17,940
as either an inbound or outbound port,

104
00:03:17,940 --> 00:03:19,800
your port is also going to get a number

105
00:03:19,800 --> 00:03:21,060
and then it's going to be assigned to one

106
00:03:21,060 --> 00:03:23,250
of three groups based on that number.

107
00:03:23,250 --> 00:03:24,840
Now this number can be anywhere

108
00:03:24,840 --> 00:03:28,950
from zero all the way up to 65,535,

109
00:03:28,950 --> 00:03:30,210
and this is a really big range,

110
00:03:30,210 --> 00:03:31,080
so it's actually been divided

111
00:03:31,080 --> 00:03:32,880
into three smaller groups.

112
00:03:32,880 --> 00:03:35,820
Our first group is known as the well-known ports.

113
00:03:35,820 --> 00:03:37,650
Now a well-known port is any port

114
00:03:37,650 --> 00:03:41,040
that is numbered between zero and 1023.

115
00:03:41,040 --> 00:03:42,690
Now these are called well-known ports

116
00:03:42,690 --> 00:03:44,430
because they're designated by IANA,

117
00:03:44,430 --> 00:03:46,740
which is the Internet Assigned Numbers Authority,

118
00:03:46,740 --> 00:03:47,970
and they're going to be able to assign it

119
00:03:47,970 --> 00:03:49,620
to a commonly used port and protocol

120
00:03:49,620 --> 00:03:51,270
that everyone can use.

121
00:03:51,270 --> 00:03:52,290
Now, for example,

122
00:03:52,290 --> 00:03:53,610
something like secure web browsing

123
00:03:53,610 --> 00:03:55,860
is something that we all use on a daily basis,

124
00:03:55,860 --> 00:03:57,870
and it uses HTTPS,

125
00:03:57,870 --> 00:04:00,330
which utilizes port 443.

126
00:04:00,330 --> 00:04:02,280
Another example of a really well-known port

127
00:04:02,280 --> 00:04:03,810
is actually port 23,

128
00:04:03,810 --> 00:04:06,330
which uses Telnet as its protocol.

129
00:04:06,330 --> 00:04:07,410
Both of these are considered

130
00:04:07,410 --> 00:04:09,120
to be well-known ports, and there are hundreds

131
00:04:09,120 --> 00:04:10,740
of others out there as well.

132
00:04:10,740 --> 00:04:11,910
Now, the second group we have

133
00:04:11,910 --> 00:04:15,827
is going to cover our ports from 1024 up to 49,151.

134
00:04:17,610 --> 00:04:20,339
This range is known as the registered port range

135
00:04:20,339 --> 00:04:22,260
because they all have to be used by vendors

136
00:04:22,260 --> 00:04:23,880
for their own proprietary protocols,

137
00:04:23,880 --> 00:04:26,280
and each vendor is going to register the number they want

138
00:04:26,280 --> 00:04:29,670
to use with IANA prior to being able to use them.

139
00:04:29,670 --> 00:04:32,520
For example, Microsoft has an SQL server

140
00:04:32,520 --> 00:04:34,560
that is using one of these registered ports.

141
00:04:34,560 --> 00:04:37,230
In this case it's port 1433,

142
00:04:37,230 --> 00:04:38,430
which is the registered port

143
00:04:38,430 --> 00:04:40,710
for the Microsoft SQL server.

144
00:04:40,710 --> 00:04:42,630
Another good example of this is if you're going to

145
00:04:42,630 --> 00:04:45,630
use the proprietary Microsoft protocol known as RDP

146
00:04:45,630 --> 00:04:47,220
or the Remote Desktop Protocol

147
00:04:47,220 --> 00:04:50,610
because it operates over port 3389.

148
00:04:50,610 --> 00:04:52,230
Now the third and final group we have

149
00:04:52,230 --> 00:04:55,200
is what's known as the dynamic and private ports.

150
00:04:55,200 --> 00:04:59,160
This uses the port range of 49,152

151
00:04:59,160 --> 00:05:01,170
all the way up to the end of our port ranges,

152
00:05:01,170 --> 00:05:04,110
which is 65,535.

153
00:05:04,110 --> 00:05:06,300
These ports can be used by any application

154
00:05:06,300 --> 00:05:07,770
at any time without having

155
00:05:07,770 --> 00:05:09,870
to be registered first with IANA.

156
00:05:09,870 --> 00:05:11,340
Now this range is usually going to be used

157
00:05:11,340 --> 00:05:12,660
by your client whenever it picks

158
00:05:12,660 --> 00:05:14,280
its own random high number port

159
00:05:14,280 --> 00:05:15,750
for its application.

160
00:05:15,750 --> 00:05:16,583
Anytime it wants

161
00:05:16,583 --> 00:05:18,210
to have a temporary outbound connection,

162
00:05:18,210 --> 00:05:19,770
this is the range we're going to be using,

163
00:05:19,770 --> 00:05:22,020
this dynamic and private port range.

164
00:05:22,020 --> 00:05:23,670
It's also very commonly used in things

165
00:05:23,670 --> 00:05:26,640
like gaming, instant messaging and chat too.

166
00:05:26,640 --> 00:05:28,440
Now, once each port is opened,

167
00:05:28,440 --> 00:05:29,580
you can now have communications

168
00:05:29,580 --> 00:05:31,770
to or from your device over that port

169
00:05:31,770 --> 00:05:33,810
using what is known as a protocol.

170
00:05:33,810 --> 00:05:35,820
Now, a protocol is a defined set of rules

171
00:05:35,820 --> 00:05:37,800
and conventions that governs the communication

172
00:05:37,800 --> 00:05:39,630
and data exchange between devices

173
00:05:39,630 --> 00:05:41,640
or systems that specifies the format

174
00:05:41,640 --> 00:05:43,050
and the sequence of messages

175
00:05:43,050 --> 00:05:43,883
that are going to be used

176
00:05:43,883 --> 00:05:45,390
for those communications.

177
00:05:45,390 --> 00:05:47,010
So for example, when I mentioned

178
00:05:47,010 --> 00:05:48,840
that we could use port 443

179
00:05:48,840 --> 00:05:51,090
for secure e-commerce website traffic,

180
00:05:51,090 --> 00:05:52,920
what I was really referring to is the fact

181
00:05:52,920 --> 00:05:55,950
that port 443 is being used with a protocol known

182
00:05:55,950 --> 00:05:57,570
as HTTPS,

183
00:05:57,570 --> 00:06:00,270
which is the Hypertext Transfer Protocol secure

184
00:06:00,270 --> 00:06:02,070
and this is going to be used to send encrypted data

185
00:06:02,070 --> 00:06:04,950
to or from a given e-commerce web server

186
00:06:04,950 --> 00:06:06,270
using data that is supported

187
00:06:06,270 --> 00:06:09,570
over HTTPS connections like HTML.

188
00:06:09,570 --> 00:06:10,980
Now for the rest of this video,

189
00:06:10,980 --> 00:06:12,540
we're going to spend just a little bit of time

190
00:06:12,540 --> 00:06:14,940
here going over each of the different well-known

191
00:06:14,940 --> 00:06:16,950
and registered ports that you should be familiar

192
00:06:16,950 --> 00:06:19,110
with as a cybersecurity professional.

193
00:06:19,110 --> 00:06:20,700
Now for the exam, you are not going to

194
00:06:20,700 --> 00:06:21,577
get a question like,

195
00:06:21,577 --> 00:06:23,190
"Which of the following ports is used

196
00:06:23,190 --> 00:06:24,780
with the SSH protocol?"

197
00:06:24,780 --> 00:06:25,800
That is too easy.

198
00:06:25,800 --> 00:06:27,360
You're not going to be able to select port 22

199
00:06:27,360 --> 00:06:28,770
and get the right answer here,

200
00:06:28,770 --> 00:06:29,880
but you will get questions

201
00:06:29,880 --> 00:06:31,440
about why a secure web connection

202
00:06:31,440 --> 00:06:33,000
is being blocked by a firewall.

203
00:06:33,000 --> 00:06:33,840
And if you don't remember

204
00:06:33,840 --> 00:06:36,180
that secure web connections rely on port 443

205
00:06:36,180 --> 00:06:38,580
to communicate, you're going to miss that question.

206
00:06:38,580 --> 00:06:41,370
Or you might get a question about RDP or SQL

207
00:06:41,370 --> 00:06:43,230
or RADIUS or something like that.

208
00:06:43,230 --> 00:06:44,550
And so all of these are things

209
00:06:44,550 --> 00:06:45,900
that are important for you to understand

210
00:06:45,900 --> 00:06:47,850
from a list of ports and protocols.

211
00:06:47,850 --> 00:06:49,080
And so we do need to take a little bit

212
00:06:49,080 --> 00:06:50,880
of time here to go over these well-known

213
00:06:50,880 --> 00:06:52,650
or registered ports, and you need to take

214
00:06:52,650 --> 00:06:54,540
some time to memorize four things

215
00:06:54,540 --> 00:06:55,980
for each given port.

216
00:06:55,980 --> 00:06:58,260
First, I want you to memorize the port number.

217
00:06:58,260 --> 00:07:00,060
Second, I want you to memorize the protocol

218
00:07:00,060 --> 00:07:02,310
used by that port by default.

219
00:07:02,310 --> 00:07:03,540
Third, I want you to know

220
00:07:03,540 --> 00:07:05,310
whether the protocol supports TCP

221
00:07:05,310 --> 00:07:06,990
or UDP connections.

222
00:07:06,990 --> 00:07:08,160
And fourth, I want you

223
00:07:08,160 --> 00:07:10,260
to know a basic description of what that port

224
00:07:10,260 --> 00:07:12,510
or protocol is going to be used for.

225
00:07:12,510 --> 00:07:14,640
Alright, with all that said, let's get started

226
00:07:14,640 --> 00:07:16,590
with our memorization of ports.

227
00:07:16,590 --> 00:07:18,630
Now, port 21 is used for FTP

228
00:07:18,630 --> 00:07:20,490
or the File Transfer Protocol.

229
00:07:20,490 --> 00:07:22,320
FTP is going to be used to transfer files

230
00:07:22,320 --> 00:07:23,340
from a host to host,

231
00:07:23,340 --> 00:07:26,670
and it operates over port 21 using TCP.

232
00:07:26,670 --> 00:07:28,260
Port 22 is going to be used

233
00:07:28,260 --> 00:07:29,430
for three different things.

234
00:07:29,430 --> 00:07:33,270
It's used for SSH, SCP and SFTP.

235
00:07:33,270 --> 00:07:34,380
SSH is going to provide us

236
00:07:34,380 --> 00:07:36,210
with secure remote terminal access

237
00:07:36,210 --> 00:07:37,530
and file transfer capabilities

238
00:07:37,530 --> 00:07:39,990
over port 22 using TCP.

239
00:07:39,990 --> 00:07:42,270
Essentially, SSH is used for remote control

240
00:07:42,270 --> 00:07:44,910
or remote access using a text-based environment

241
00:07:44,910 --> 00:07:46,500
to a remote server.

242
00:07:46,500 --> 00:07:47,880
SCP is going to provide

243
00:07:47,880 --> 00:07:50,790
with you a secure copy functions over port 22

244
00:07:50,790 --> 00:07:53,550
and SFTP will provide secure file transfers

245
00:07:53,550 --> 00:07:55,530
over port 22 as well.

246
00:07:55,530 --> 00:07:57,030
Next we have port 23,

247
00:07:57,030 --> 00:07:58,500
which is going to be used for Telnet,

248
00:07:58,500 --> 00:07:59,370
and this is a protocol

249
00:07:59,370 --> 00:08:01,200
for remotely accessing network devices

250
00:08:01,200 --> 00:08:04,290
and it operates over port 23 using TCP.

251
00:08:04,290 --> 00:08:07,410
Telnet is the older version of SSH essentially.

252
00:08:07,410 --> 00:08:08,670
It's going to allow you to have remote control

253
00:08:08,670 --> 00:08:10,230
of a computer to be able to access it

254
00:08:10,230 --> 00:08:11,520
over a text-based connection,

255
00:08:11,520 --> 00:08:13,470
but it is unencrypted and considered

256
00:08:13,470 --> 00:08:15,270
to be insecure, so you should not be using

257
00:08:15,270 --> 00:08:16,110
it these days.

258
00:08:16,110 --> 00:08:17,010
But it is important to know

259
00:08:17,010 --> 00:08:18,990
that port 23 is Telnet, because a lot

260
00:08:18,990 --> 00:08:21,090
of exam questions will focus on the ability

261
00:08:21,090 --> 00:08:23,160
of using remote control over port 23

262
00:08:23,160 --> 00:08:25,080
and then ask you how you can better secure it

263
00:08:25,080 --> 00:08:26,940
and the answer would be to close Telnet

264
00:08:26,940 --> 00:08:29,220
and then instead open an SSH port.

265
00:08:29,220 --> 00:08:31,320
Next one we have is port 25.

266
00:08:31,320 --> 00:08:33,419
Port 25 is used for SMTP

267
00:08:33,419 --> 00:08:35,400
or the Simple Mail Transfer Protocol

268
00:08:35,400 --> 00:08:36,900
that's responsible for sending emails

269
00:08:36,900 --> 00:08:39,659
over port 25 using TCP.

270
00:08:39,659 --> 00:08:41,970
Port 53 is going to be used for DNS

271
00:08:41,970 --> 00:08:43,620
or the Domain Name System.

272
00:08:43,620 --> 00:08:45,420
This is going to be used to translate domain names

273
00:08:45,420 --> 00:08:47,190
into IP addresses and it functions

274
00:08:47,190 --> 00:08:51,690
over port 53 using both TCP and UDP connections.

275
00:08:51,690 --> 00:08:54,330
Port 69 is going to be used for TFTP

276
00:08:54,330 --> 00:08:56,400
or the Trivial File Transfer Protocol,

277
00:08:56,400 --> 00:08:58,233
which is a simplified file transfer protocol

278
00:08:58,233 --> 00:08:59,400
that is often used

279
00:08:59,400 --> 00:09:01,560
with network-based operating systems.

280
00:09:01,560 --> 00:09:02,393
This is going to operate

281
00:09:02,393 --> 00:09:05,730
over port 69 using a UDP connection.

282
00:09:05,730 --> 00:09:07,440
Port 80 is the next one we have,

283
00:09:07,440 --> 00:09:09,180
and this is used for HTTP

284
00:09:09,180 --> 00:09:11,400
or the Hypertext Transfer Protocol.

285
00:09:11,400 --> 00:09:13,770
HTTP is used for retrieving webpages

286
00:09:13,770 --> 00:09:16,470
and it operates over page 80 using TCP

287
00:09:16,470 --> 00:09:18,360
in an unencrypted mode.

288
00:09:18,360 --> 00:09:21,330
Next we have port 88, which is used for Kerberos.

289
00:09:21,330 --> 00:09:23,520
Kerberos is a network authentication protocol

290
00:09:23,520 --> 00:09:26,400
that operates over port 88 using UDP.

291
00:09:26,400 --> 00:09:28,650
Port 110 is used for POP3

292
00:09:28,650 --> 00:09:31,500
or the Post Office Protocol Version Three.

293
00:09:31,500 --> 00:09:32,670
POP3 is going to be responsible

294
00:09:32,670 --> 00:09:34,320
for retrieving email from a server

295
00:09:34,320 --> 00:09:36,120
and it operates over port one 10

296
00:09:36,120 --> 00:09:38,220
using TCP connections.

297
00:09:38,220 --> 00:09:41,340
Port 119 is going to be used for NNTP

298
00:09:41,340 --> 00:09:42,900
or the Network News Transfer Protocol,

299
00:09:42,900 --> 00:09:44,940
and it's used for accessing news groups

300
00:09:44,940 --> 00:09:48,570
and it operates over port 119 using TCP.

301
00:09:48,570 --> 00:09:52,170
Next we have port 135, which is used for RPC

302
00:09:52,170 --> 00:09:54,420
or Remote Procedure Call facilities.

303
00:09:54,420 --> 00:09:56,310
This is going to facilitate your communication

304
00:09:56,310 --> 00:09:57,990
between different system processes

305
00:09:57,990 --> 00:10:02,340
and it operates over port 135 using TCP and UDP.

306
00:10:02,340 --> 00:10:04,530
Often you'll see RPC used as part

307
00:10:04,530 --> 00:10:06,630
of the Windows file sharing system.

308
00:10:06,630 --> 00:10:10,500
Next we have ports 137, 138 and 139,

309
00:10:10,500 --> 00:10:12,690
which are all used for NetBIOS.

310
00:10:12,690 --> 00:10:14,640
NetBIOS is a network protocol suite

311
00:10:14,640 --> 00:10:18,666
and it operates over ports 137, 138 and 139

312
00:10:18,666 --> 00:10:20,670
using UDP and TCP.

313
00:10:20,670 --> 00:10:21,900
NetBIOS is used inside

314
00:10:21,900 --> 00:10:23,679
of a Windows domain environment

315
00:10:23,679 --> 00:10:24,570
for you to be able to share things

316
00:10:24,570 --> 00:10:26,610
like internal network names as well

317
00:10:26,610 --> 00:10:28,200
as doing file and printer sharing

318
00:10:28,200 --> 00:10:30,060
in a local Windows environment.

319
00:10:30,060 --> 00:10:33,660
Next we have port 143, which is used for IMAP.

320
00:10:33,660 --> 00:10:36,240
IMAP or the Internet Message Access Protocol

321
00:10:36,240 --> 00:10:38,790
allows for accessing email messages on a server

322
00:10:38,790 --> 00:10:41,010
and be able to operate over port 143

323
00:10:41,010 --> 00:10:43,260
using a TCP connection.

324
00:10:43,260 --> 00:10:46,860
Next we have port 161, which is used for SNMP

325
00:10:46,860 --> 00:10:48,687
or the Simple Network Management Protocol

326
00:10:48,687 --> 00:10:51,150
and SNMP is used to manage network devices

327
00:10:51,150 --> 00:10:54,660
and it operates over port 161 using UDP.

328
00:10:54,660 --> 00:10:57,690
Port 162 is used for SNMP Traps

329
00:10:57,690 --> 00:10:59,310
and SNMP Traps are responsible

330
00:10:59,310 --> 00:11:01,260
for sending SNMP Trap messages

331
00:11:01,260 --> 00:11:04,800
and it operates over port 162 using UDP.

332
00:11:04,800 --> 00:11:07,020
Next we have port 389.

333
00:11:07,020 --> 00:11:09,180
Port 389 is going to be used for LDAP

334
00:11:09,180 --> 00:11:11,790
or the Lightweight Directory Access Protocol.

335
00:11:11,790 --> 00:11:12,840
This is going to be able to help you

336
00:11:12,840 --> 00:11:14,670
with directory services and it operates

337
00:11:14,670 --> 00:11:17,790
over port 389 using TCP.

338
00:11:17,790 --> 00:11:20,850
Port 443 is going to be used for HTTPS

339
00:11:20,850 --> 00:11:23,550
or the Hypertext Transfer Protocol Secure.

340
00:11:23,550 --> 00:11:24,383
And this provides us

341
00:11:24,383 --> 00:11:26,370
with a secure web communication process

342
00:11:26,370 --> 00:11:29,460
that operates over port 443 using TCP.

343
00:11:29,460 --> 00:11:30,660
If you ever go to a website

344
00:11:30,660 --> 00:11:32,460
and it has that little lock in the corner,

345
00:11:32,460 --> 00:11:35,460
that means you're using an HTTPS connection.

346
00:11:35,460 --> 00:11:37,530
Next we have port 445.

347
00:11:37,530 --> 00:11:40,050
Port 445 is going to be used for SMB

348
00:11:40,050 --> 00:11:41,640
or the Server Message Block,

349
00:11:41,640 --> 00:11:42,570
and it's going to be used for file

350
00:11:42,570 --> 00:11:44,340
and printer sharing over a network

351
00:11:44,340 --> 00:11:47,880
and operates using port 445 using TCP.

352
00:11:47,880 --> 00:11:50,940
Next we have ports 465 and 587,

353
00:11:50,940 --> 00:11:53,460
which are going to be used for SMTPS.

354
00:11:53,460 --> 00:11:56,670
SMTPS is also known as SMTP Secure

355
00:11:56,670 --> 00:11:57,503
and it provides us

356
00:11:57,503 --> 00:11:59,460
with secure SMTP communications

357
00:11:59,460 --> 00:12:02,041
to send our emails over port 465

358
00:12:02,041 --> 00:12:04,320
or 587 using either SSL

359
00:12:04,320 --> 00:12:07,560
or TLS and a TCP connection.

360
00:12:07,560 --> 00:12:09,750
Next we have port 514.

361
00:12:09,750 --> 00:12:11,940
Port 514 is used for Syslog

362
00:12:11,940 --> 00:12:13,920
and it's a protocol for sending log messages

363
00:12:13,920 --> 00:12:15,960
and it operates over port 514

364
00:12:15,960 --> 00:12:17,970
using a UDP connection.

365
00:12:17,970 --> 00:12:20,280
Next we have port 636.

366
00:12:20,280 --> 00:12:24,900
Port 636 is used for LDAP Secure or LDAPS.

367
00:12:24,900 --> 00:12:25,733
This allows us

368
00:12:25,733 --> 00:12:27,930
to have our LDAP directory communications happening

369
00:12:27,930 --> 00:12:30,840
over an SSL or TLS connection that is encrypted

370
00:12:30,840 --> 00:12:32,790
and operating over port 636

371
00:12:32,790 --> 00:12:34,950
using a TCP connection.

372
00:12:34,950 --> 00:12:37,350
Next, we have port 993.

373
00:12:37,350 --> 00:12:39,330
Port 993 is used for IMAPS

374
00:12:39,330 --> 00:12:41,190
or the Internet Message Access Protocol

375
00:12:41,190 --> 00:12:43,560
over SSL or TLS and essentially,

376
00:12:43,560 --> 00:12:45,810
this is the secure version of IMAP.

377
00:12:45,810 --> 00:12:46,643
This is going to be used

378
00:12:46,643 --> 00:12:49,410
to do the secure email retrieval over port 993

379
00:12:49,410 --> 00:12:51,510
using a TCP connection.

380
00:12:51,510 --> 00:12:53,790
Next we have port 995.

381
00:12:53,790 --> 00:12:56,430
Port 995 is used for POP3S.

382
00:12:56,430 --> 00:12:58,470
This is the Post Office Protocol Version Three

383
00:12:58,470 --> 00:13:00,180
over SSL or TLS.

384
00:13:00,180 --> 00:13:02,430
This allows us to have secure email retrieval

385
00:13:02,430 --> 00:13:05,520
using a POP3 protocol over port 995

386
00:13:05,520 --> 00:13:07,620
using a TCP connection.

387
00:13:07,620 --> 00:13:10,350
Next we have port 1433.

388
00:13:10,350 --> 00:13:13,121
Port 1433 is used for Microsoft SQL

389
00:13:13,121 --> 00:13:14,730
to facilitate communication

390
00:13:14,730 --> 00:13:17,100
with our Microsoft SQL server and it operates

391
00:13:17,100 --> 00:13:20,850
over port 1433 using a TCP connection.

392
00:13:20,850 --> 00:13:24,690
Next we have ports 1645 and 1646.

393
00:13:24,690 --> 00:13:28,650
Now ports 1645 and 1646 are used for RADIUS

394
00:13:28,650 --> 00:13:30,930
using the TCP version of RADIUS.

395
00:13:30,930 --> 00:13:32,070
And RADIUS is a protocol

396
00:13:32,070 --> 00:13:33,330
for remote authentication,

397
00:13:33,330 --> 00:13:34,890
authorization and accounting

398
00:13:34,890 --> 00:13:38,340
that operates over ports 1645 and 1646

399
00:13:38,340 --> 00:13:40,200
using a TCP connection.

400
00:13:40,200 --> 00:13:43,890
Next we have ports 1812 and 1813,

401
00:13:43,890 --> 00:13:45,210
which are going to be used for RADIUS

402
00:13:45,210 --> 00:13:47,340
when it uses a UDP session.

403
00:13:47,340 --> 00:13:49,170
Now RADIUS again is going to function

404
00:13:49,170 --> 00:13:53,160
over ports 1812 and 1813 using UDP

405
00:13:53,160 --> 00:13:56,160
if we want to use UDP instead of TCP.

406
00:13:56,160 --> 00:13:58,148
Next we have port 3389.

407
00:13:58,148 --> 00:14:00,990
Port 3389 is used by RDP

408
00:14:00,990 --> 00:14:02,610
or the Remote Desktop Protocol

409
00:14:02,610 --> 00:14:04,560
and it enables remote desktop access

410
00:14:04,560 --> 00:14:06,420
and operates over port 3389

411
00:14:06,420 --> 00:14:08,400
using a TCP connection.

412
00:14:08,400 --> 00:14:11,190
And finally we have port 6514

413
00:14:11,190 --> 00:14:14,640
and port 6514 is going to be used for a Syslog TLS,

414
00:14:14,640 --> 00:14:16,260
which is a secure and encrypted version

415
00:14:16,260 --> 00:14:19,230
of Syslog that operates over port 6514

416
00:14:19,230 --> 00:14:21,210
using a TCP connection.

417
00:14:21,210 --> 00:14:22,590
Now, I know that was a lot

418
00:14:22,590 --> 00:14:23,940
of information I just provided

419
00:14:23,940 --> 00:14:25,860
in a very short amount of time.

420
00:14:25,860 --> 00:14:27,330
After watching this video once,

421
00:14:27,330 --> 00:14:28,350
I know you will not have

422
00:14:28,350 --> 00:14:29,400
all these ports memorized

423
00:14:29,400 --> 00:14:30,510
that I just went through.

424
00:14:30,510 --> 00:14:32,160
So I do recommend you take the time

425
00:14:32,160 --> 00:14:33,750
to make a list and test yourself

426
00:14:33,750 --> 00:14:35,880
over and over again on these ports.

427
00:14:35,880 --> 00:14:37,650
This is critical information to answer a lot

428
00:14:37,650 --> 00:14:39,720
of questions on the exam, either directly

429
00:14:39,720 --> 00:14:42,240
or indirectly as you're going to see on test day.

430
00:14:42,240 --> 00:14:44,040
Remember, you can rewatch this video

431
00:14:44,040 --> 00:14:45,390
as many times as you like

432
00:14:45,390 --> 00:14:47,550
to learn these different ports and protocols.

433
00:14:47,550 --> 00:14:48,600
Now with that being said,

434
00:14:48,600 --> 00:14:50,250
I do like the old fashioned method

435
00:14:50,250 --> 00:14:51,540
of making some flashcards

436
00:14:51,540 --> 00:14:54,090
to testing yourself on these ports and protocols.

437
00:14:54,090 --> 00:14:56,310
If you do that, I would write down the protocol

438
00:14:56,310 --> 00:14:59,160
on one side like HTTP, and then I want you

439
00:14:59,160 --> 00:15:00,720
to flip it over and then on the other side,

440
00:15:00,720 --> 00:15:01,800
I want you to have the port number

441
00:15:01,800 --> 00:15:05,460
and the connection type like port 80 TCP.

442
00:15:05,460 --> 00:15:06,990
This way you'll be able to know

443
00:15:06,990 --> 00:15:08,313
what you have on both sides

444
00:15:08,313 --> 00:15:09,450
and you can take the time

445
00:15:09,450 --> 00:15:10,860
to learn these ports and protocols

446
00:15:10,860 --> 00:15:12,420
before you take the exam.

447
00:15:12,420 --> 00:15:14,010
I promise you, taking the time

448
00:15:14,010 --> 00:15:15,600
to learn these ports and protocols is going

449
00:15:15,600 --> 00:15:17,040
to help you a lot come test day

450
00:15:17,040 --> 00:15:18,450
as well as in your future career

451
00:15:18,450 --> 00:15:20,050
as a cybersecurity professional.

