Scanlanmaxfield guide to your own network

Walkthrough

How to check which ports are open on your own computer

List listening ports on your own PC with netstat, Get-NetTCPConnection, lsof or ss, match them to programs, then confirm from a second machine.

A firewall prompt pops up asking whether some program may “accept incoming connections”, and you realize you have no idea what your computer is actually offering to the network. Or an IT checklist from your insurer asks you to confirm that Remote Desktop isn’t exposed. Both questions have the same answer: find out which ports are open, then decide which ones should be.

There are two views of this, and you need both. The inside view asks the operating system which programs are listening. The outside view asks, from another machine on your network, which of those ports actually answer through the firewall. We’ll do them in that order, on a computer you own or manage.

A two-minute refresher on ports

A port is a numbered door on an IP address, from 0 to 65535, for TCP and separately for UDP. A program “listens” on a port to receive connections: a web server on 80 or 443, Remote Desktop on 3389, Windows file sharing on 445. “Open” means something is listening and the firewall lets traffic reach it. A port can be listening but blocked, which is exactly why the outside check matters.

Also note the address a program listens on. 127.0.0.1 (or ::1) means the computer only talks to itself, so nothing else on the network can reach it. 0.0.0.0 (or ::) means every network interface, including your Wi-Fi.

Step 1: The inside view on Windows

Open Command Prompt or PowerShell as administrator (so you can see process details for every service).

  1. List every listening TCP port with the owning process ID:

    netstat -ano | findstr LISTENING

    The columns are protocol, local address:port, remote address, state, and PID.

  2. Turn a PID into a program name:

    tasklist /fi "PID eq 4312"
  3. Or do it all in one go in PowerShell, which reads more cleanly:

    Get-NetTCPConnection -State Listen |
      Select-Object LocalAddress, LocalPort, OwningProcess,
        @{n='Process';e={(Get-Process -Id $_.OwningProcess).ProcessName}} |
      Sort-Object LocalPort
  4. For UDP, which has no “listening” state, use:

    Get-NetUDPEndpoint | Sort-Object LocalPort

On a fresh Windows 11 machine you’ll typically see 135 (RPC), 445 (SMB), 139 if NetBIOS is on, 5040 and 7680 (the Delivery Optimization service that shares updates between PCs), plus a few high-numbered ports belonging to svchost and lsass. PID 4 is the Windows kernel (“System”), which owns SMB and anything served through HTTP.sys. None of that is alarming by itself; what matters is anything you didn’t expect, especially 3389 (Remote Desktop), 5900 (VNC), 22 (SSH) or random web ports opened by a tool someone tried once and forgot.

Step 2: The inside view on macOS and Linux

On macOS, in Terminal:

sudo lsof -iTCP -sTCP:LISTEN -n -P

-n -P keeps addresses and ports numeric, so the list appears quickly. Expect entries such as rapportd (Continuity/Handoff) and ControlCenter on 5000/7000 for AirPlay Receiver.

On Linux:

sudo ss -tulpn

That prints TCP and UDP listeners with the owning process. Older distributions may still offer netstat -tulpn from the net-tools package.

Step 3: The outside view from a second machine

The inside list tells you what is listening. To know what the network can actually reach, scan the computer from another device on the same LAN. This is where a GUI scanner earns its place.

Before you scan: Scan your own computers or ones you administer. Port-scanning machines you don’t own, including those on a shared office or dorm network, can breach policy or law.

With Advanced Port Scanner on a second Windows PC:

  1. Get it from the vendor’s product page (our /where-to-get page explains how to check the publisher signature before running anything).
  2. Enter the target’s IP address, for example 192.168.1.50, in the range box.
  3. Keep the default port list for a quick pass, or enter 1-65535 for a thorough one; a full range on a single host takes a minute or two on a wired LAN.
  4. Click Scan. Expand the host to see each open port and, where it can tell, the service name and version.

If you are comfortable with a command line, Nmap gives a more detailed answer:

nmap -p- -sV 192.168.1.50

-p- checks all 65,535 TCP ports; -sV asks each open one what software is behind it. Add -sU --top-ports 50 if UDP matters to you, but expect UDP results to be slower and less certain. Our comparison of Nmap vs Advanced Port Scanner explains when each is the better fit, and the Port & Service Scanners category lists the alternatives.

Compare the two lists. A port that appears inside but not outside is being blocked by the firewall, which is often what you want. A port that appears outside and surprises you is your action item.

Step 4: Close what you don’t need

  1. Stop the program or service first. Uninstall the forgotten tool, or open services.msc and set an unneeded service to Disabled. Closing the listener is cleaner than hiding it.
  2. Then tighten the firewall. In Windows Defender Firewall, check the inbound rules for the port and restrict them to the Private profile or to specific addresses. On macOS, System Settings → Network → Firewall; on Linux, ufw or firewalld.
  3. Check your router. Your PC’s ports only reach the internet if the router forwards them. Look at Port Forwarding and UPnP in the router admin page and remove forwards you don’t recognize. Turning UPnP off stops programs from opening forwards on their own.
  4. Scan again from the second machine to confirm the port no longer answers.

Common mistakes

If the scan turns up devices you don’t recognize rather than ports, switch to our guide on identifying an unknown device on your network.

Tool used in this walkthrough