Standard ports for web server The 2019 Stack Overflow Developer Survey Results Are InMSMQ Firewall PortsWhat ports should be left open on a web server?TCP/IP ports necessary for CIFS/SMB operationPorts used for Lync Edge serverForefront TMG 2010 RDP Connections without non-standard portsASA 5505 8.4 open ports for subnetWhich ports for IPSEC/LT2P?Outbound ports for a firewall for webserver and db serverTest port reachability from a remote host even though the port is not bound to a service?How do I block my server from performing port scans?

One word riddle: Vowel in the middle

Time travel alters history but people keep saying nothing's changed

Is a "Democratic" Oligarchy-Style System Possible?

For what reasons would an animal species NOT cross a *horizontal* land bridge?

Why can Shazam fly?

Output the Arecibo Message

Why hard-Brexiteers don't insist on a hard border to prevent illegal immigration after Brexit?

How to support a colleague who finds meetings extremely tiring?

Falsification in Math vs Science

Why did Acorn's A3000 have red function keys?

Is "plugging out" electronic devices an American expression?

Does a dangling wire really electrocute me if I'm standing in water?

Does the shape of a die affect the probability of a number being rolled?

Have you ever entered Singapore using a different passport or name?

Can a flute soloist sit?

Why isn't the circumferential light around the M87 black hole's event horizon symmetric?

Lightning Grid - Columns and Rows?

Is an up-to-date browser secure on an out-of-date OS?

Why do UK politicians seemingly ignore opinion polls on Brexit?

What is the closest word meaning "respect for time / mindful"

When should I buy a clipper card after flying to OAK?

The difference between dialogue marks

Are spiders unable to hurt humans, especially very small spiders?

What does ひと匙 mean in this manga and has it been used colloquially?



Standard ports for web server



The 2019 Stack Overflow Developer Survey Results Are InMSMQ Firewall PortsWhat ports should be left open on a web server?TCP/IP ports necessary for CIFS/SMB operationPorts used for Lync Edge serverForefront TMG 2010 RDP Connections without non-standard portsASA 5505 8.4 open ports for subnetWhich ports for IPSEC/LT2P?Outbound ports for a firewall for webserver and db serverTest port reachability from a remote host even though the port is not bound to a service?How do I block my server from performing port scans?



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I'm using Hetzner for a server which only needs 80/443 and 22 accessible to the outside world. When I use the Hetzner firewall template, it also adds:



  • protocol icmp, which I think is for ping

  • ports 32768-65535 are open with a tcp flag of 'ack'

AWS seems to close down everything, including ping.



  • Is there any reason to have ports 32768-65535 open and what does 'ack' mean ?

  • Should protocol icmp be disallowed?

The Nginx server is running https and 80 is redirected to 443. Is it best practice to leave 80 open and redirecting to 443, in case traffic comes in on 80, or should 80 also be closed?



Screenshot of ports










share|improve this question

















  • 1





    For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

    – Lenniey
    13 hours ago


















1















I'm using Hetzner for a server which only needs 80/443 and 22 accessible to the outside world. When I use the Hetzner firewall template, it also adds:



  • protocol icmp, which I think is for ping

  • ports 32768-65535 are open with a tcp flag of 'ack'

AWS seems to close down everything, including ping.



  • Is there any reason to have ports 32768-65535 open and what does 'ack' mean ?

  • Should protocol icmp be disallowed?

The Nginx server is running https and 80 is redirected to 443. Is it best practice to leave 80 open and redirecting to 443, in case traffic comes in on 80, or should 80 also be closed?



Screenshot of ports










share|improve this question

















  • 1





    For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

    – Lenniey
    13 hours ago














1












1








1








I'm using Hetzner for a server which only needs 80/443 and 22 accessible to the outside world. When I use the Hetzner firewall template, it also adds:



  • protocol icmp, which I think is for ping

  • ports 32768-65535 are open with a tcp flag of 'ack'

AWS seems to close down everything, including ping.



  • Is there any reason to have ports 32768-65535 open and what does 'ack' mean ?

  • Should protocol icmp be disallowed?

The Nginx server is running https and 80 is redirected to 443. Is it best practice to leave 80 open and redirecting to 443, in case traffic comes in on 80, or should 80 also be closed?



Screenshot of ports










share|improve this question














I'm using Hetzner for a server which only needs 80/443 and 22 accessible to the outside world. When I use the Hetzner firewall template, it also adds:



  • protocol icmp, which I think is for ping

  • ports 32768-65535 are open with a tcp flag of 'ack'

AWS seems to close down everything, including ping.



  • Is there any reason to have ports 32768-65535 open and what does 'ack' mean ?

  • Should protocol icmp be disallowed?

The Nginx server is running https and 80 is redirected to 443. Is it best practice to leave 80 open and redirecting to 443, in case traffic comes in on 80, or should 80 also be closed?



Screenshot of ports







firewall hetzner






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked 13 hours ago









ardochhighardochhigh

1221112




1221112







  • 1





    For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

    – Lenniey
    13 hours ago













  • 1





    For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

    – Lenniey
    13 hours ago








1




1





For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

– Lenniey
13 hours ago






For tcp ack on Hetzner it's right there on their homepage: wiki.hetzner.de/index.php/Robot_Firewall/… including an example.

– Lenniey
13 hours ago











1 Answer
1






active

oldest

votes


















4














Port 80: Port 80 needs to be open so that the Nginx can redirect to port 443. If you block port 80 clients trying to connect via http will time out.



There is a website dedicated to argue that ICMP should not be blocked.



ACK is the last step in the three-way handshake TCP uses to establish a connection. The port range 32768-65535 is for ephemeral ports. So that firewall rule should not be touched.



These rules look different from AWS security group rules because AWS security group rule are set for inbound or outbound traffic.






share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962412%2fstandard-ports-for-web-server%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    4














    Port 80: Port 80 needs to be open so that the Nginx can redirect to port 443. If you block port 80 clients trying to connect via http will time out.



    There is a website dedicated to argue that ICMP should not be blocked.



    ACK is the last step in the three-way handshake TCP uses to establish a connection. The port range 32768-65535 is for ephemeral ports. So that firewall rule should not be touched.



    These rules look different from AWS security group rules because AWS security group rule are set for inbound or outbound traffic.






    share|improve this answer



























      4














      Port 80: Port 80 needs to be open so that the Nginx can redirect to port 443. If you block port 80 clients trying to connect via http will time out.



      There is a website dedicated to argue that ICMP should not be blocked.



      ACK is the last step in the three-way handshake TCP uses to establish a connection. The port range 32768-65535 is for ephemeral ports. So that firewall rule should not be touched.



      These rules look different from AWS security group rules because AWS security group rule are set for inbound or outbound traffic.






      share|improve this answer

























        4












        4








        4







        Port 80: Port 80 needs to be open so that the Nginx can redirect to port 443. If you block port 80 clients trying to connect via http will time out.



        There is a website dedicated to argue that ICMP should not be blocked.



        ACK is the last step in the three-way handshake TCP uses to establish a connection. The port range 32768-65535 is for ephemeral ports. So that firewall rule should not be touched.



        These rules look different from AWS security group rules because AWS security group rule are set for inbound or outbound traffic.






        share|improve this answer













        Port 80: Port 80 needs to be open so that the Nginx can redirect to port 443. If you block port 80 clients trying to connect via http will time out.



        There is a website dedicated to argue that ICMP should not be blocked.



        ACK is the last step in the three-way handshake TCP uses to establish a connection. The port range 32768-65535 is for ephemeral ports. So that firewall rule should not be touched.



        These rules look different from AWS security group rules because AWS security group rule are set for inbound or outbound traffic.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered 13 hours ago









        Henrik PingelHenrik Pingel

        4,60021530




        4,60021530



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962412%2fstandard-ports-for-web-server%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Куамањотепек (Чилапа де Алварез) Садржај Становништво Види још Референце Спољашње везе Мени за навигацију17°19′47″N 99°1′51″W / 17.32972° СГШ; 99.03083° ЗГД / 17.32972; -99.0308317°19′47″N 99°1′51″W / 17.32972° СГШ; 99.03083° ЗГД / 17.32972; -99.030838877656„Instituto Nacional de Estadística y Geografía”„The GeoNames geographical database”Мексичка насељапроширитиуу

            How to make RAID controller rescan devices The 2019 Stack Overflow Developer Survey Results Are InLSI MegaRAID SAS 9261-8i: Disk isn't recognized after replacementHow to monitor the hard disk status behind Dell PERC H710 Raid Controller with CentOS 6?LSI MegaRAID - Recreate missing RAID 1 arrayext. 2-bay USB-Drive with RAID: btrfs RAID vs built-in RAIDInvalid SAS topologyDoes enabling JBOD mode on LSI based controllers affect existing logical disks/arrays?Why is there a shift between the WWN reported from the controller and the Linux system?Optimal RAID 6+0 Setup for 40+ 4TB DisksAccidental SAS cable removal

            Срби Садржај Географија Етимологија Генетика Историја Језик Религија Популација Познати Срби Види још Напомене Референце Извори Литература Спољашње везе Мени за навигацијууrs.one.un.orgАрхивираноАрхивирано из оригиналаПопис становништва из 2011. годинеCOMMUNITY PROFILE: SERB COMMUNITY„1996 population census in Bosnia and Herzegovina”„CIA - The World Factbook - Bosnia and Herzegovina”American FactFinder - Results„2011 National Household Survey: Data tables”„Srbi u Nemačkoj | Srbi u Njemačkoj | Zentralrat der Serben in Deutschland”оригинала„Vesti online - Srpski informativni portal”„The Serbian Diaspora and Youth: Cross-Border Ties and Opportunities for Development”оригиналаSerben-Demo eskaliert in Wien„The People of Australia – Statistics from the 2011 Census”„Erstmals über eine Million EU- und EFTA Angehörige in der Schweiz”STANOVNIŠTVO PREMA NARODNOSTI – DETALJNA KLASIFIKACIJA – POPIS 2011.(Завод за статистику Црне Горе)title=Présentation de la République de SerbieSerbian | EthnologuePopulation by ethnic affiliation, Slovenia, Census 1953, 1961, 1971, 1981, 1991 and 2002Попис на населението, домаќинствата и становите во Република Македонија, 2002: Дефинитивни податоциALBANIJA ETNIČKI ČISTI SRBE: Iščezlo 100.000 ljudi pokrštavanjem, kao što su to radile ustaše u NDH! | Telegraf – Najnovije vestiИз удаљене Аргентине„Tab11. Populaţia stabilă după etnie şi limba maternă, pe categorii de localităţi”Суседи броје Србе„Srpska Dijaspora”оригиналаMinifacts about Norway 2012„Statistiques - 01.06.2008”ПРЕДСЕДНИК СРБИЈЕ СА СРБИМА У БРАТИСЛАВИСлавка Драшковић: Многа питања Срба у Црној Гори нерешенаThe Spread of the SlavesGoogle Book„Distribution of European Y-chromosome DNA (Y-DNA) haplogroups by country in percentage”American Journal of Physical Anthropology 142:380–390 (2010)„Архивирана копија”оригинала„Haplogroup I2 (Y-DNA)”„Архивирана копија”оригиналаVTS 01 1 - YouTubeПрви сукоби Срба и Турака - Политикин забавникАрхивираноConstantine Porphyrogenitus: De Administrando ImperioВизантиски извори за историју народа ЈугославијеDe conversione Croatorum et Serborum: A Lost SourceDe conversione Croatorum et Serborum: Изгубљени извор Константина ПорфирогенитаИсторија српске државностиИсторија српског народаСрбофобија и њени извориСерска област после Душанове смртиИсторија ВизантијеИсторија средњовековне босанске државеСрби међу европским народимаСрби у средњем векуМедијиПодациууууу00577267