FTP [FILE TRANSFER PROTOCOL] - transfer files between systems tcp/20 & 21, SFTP [SECURE FILE TRAANSFER PROTOCOL] - encrypted transfer files between systems, uses SSH, ALLOWS FOR FILE MANAGEMENT tcp/22, SSH [SECURE SHELL] - encrypted text based console communication tcp/22, TELNET - non-encrypted console communication, identical to ssh tcp/23, SMTP [SIMPLE MAIL TRANSFER PROTOCOL] - sending emails or server to server email transfer tcp/25 = unencrypted, DNS [DOMAIN NAME SYSTEM] - FQDN, converts names to IP address udp/53, DHCP [DYNAMIC HOST CONFIGURATION PROTOCOL] - automated configuration of IP address, subnet mask etc; assigned by MAC address udp/67, udp/68, TFTP [TRIVIAL FILE TRANSFER PROTOCOL] - no authentication, very simple file transfer. used with system that have no IP address udp/69, HTTP [HYPERTEXT TRANSFER PROTOCOL] - web server communication tcp/80, NTP [NETWORK TIME PROTOCOL] - protocol that enables time sychronization between devices udp/123 , SNMP [SIMPLE NETWORK MANAGEMENT PROTOCOL] - gather statistic from network devices "how much traffic between a & b?" udp/161, LDAP [LIGHTWEIGHT DIRECTORY ACCESS PROTOCOL] - database of devices and user used to retrieve information about network relationships tcp/389, HTTPS [HYPERTEXT TRANSFER PROTOCOL SECURE] - encrypted web server communication tcp/443, SMB [SERVER MESSAGE BLOCK] - only used by Microsoft, allows you to share files or printers and authenticate to the network or lock files; also called CIFS. tcp/445, SYSLOG - usually used in conjunction with a SIEM, collects log info udp/514, SMTPS [SIMPLE MAIL TRANSFER PROTOCOL SECURE] - sending emails or server to server email transfer tcp/587 encrypted, LDAPS [ LIGHTWEIGHT DIRECTORY ACCESS PROTOCOL over SSL] - uses SSL database of devices and user used to retrieve information about network relationships tcp/636, SQL [STRUCTURED QUERY LANGUAGE] - a standard language across database servers that allow you to query and retrieve information from databases, RDP [REMOTE DESKTOP PROTOCOL] - share a desktop from a remote location tcp/3389, SIP [SESSION INITIATION PROTOCOL] - setup and manage VoIP session tcp/5060 & tcp/5061, ICMP [INTERNET CONTROL MESSAGE PROTOCOL] - not used for data transfer, devices can request and reply to administrative requests. think 'ping' lets you know TTL expiration or if a network is not reachable, GRE [GENERIC ROUTING ENCAPSULATION] - the 'tunnel' between two endpoints usually vpn to vpn, no built-in encryption. , IPSec - security for OSI layer 3, authentication and encryption for every packet typically used with vpn tunnels, AH [AUTHENTICATION HEADER] - core IPsec protocol, validates info you recieve over an IPsec tunnel non encrypted, ESP [ENCAPSULATING SECURITY PAYLOAD] - core IPsec protocol, encrypts data you're sending over an IPsec tunnel, IKE [INTERNET KEY EXCHANGE] - allows both side of a connection to agree on encryption/decryption keys, builds a security associate (SA) , VPN CONCENTRATOR - a device that encrypts and decrypts VPN traffic, often integrated into a firewall,

1.4 PROTOCOLS AND PORT NUMBER + definitions

Leaderboard

Visual style

Options

Switch template

Continue editing: ?