TCP 端口检查
检查任意主机上的 TCP 端口是开放、关闭还是被过滤
本页提供关于 TCP 端口检测的原创、经人工审校的内容,解释连接状态、常见服务端口,以及如何区分关闭端口与被防火墙过滤的端口。
TCP port scanning is a network diagnostic technique used to determine whether specific TCP ports on a target host are open, closed, or filtered. This technology is crucial for network management, security auditing, and troubleshooting.
主要用途:
- 网络服务发现:识别目标主机上运行的网络服务
- 安全审计:检查不必要的开放端口并评估安全风险
- 故障排查:诊断网络连通性问题和服务可用性
- 防火墙测试:验证防火墙规则配置是否正确
- 合规检查:确保系统符合安全策略要求
TCP 端口状态:
开放
端口接受连接,有服务正在该端口监听
关闭
端口不接受连接,没有服务监听
被过滤
防火墙或其他网络设备阻止了连接
超时
连接请求超时,可能被丢弃或延迟
响应时间
Time from sending connection request to receiving response, measured in milliseconds. Lower response times indicate better network performance.
- < 50ms:优秀
- 50-100ms:良好
- 100-200ms:一般
- > 200ms:缓慢
服务检测
Identify possible service types based on port numbers. Common services include:
版本检测
Attempt to identify service versions running on open ports. This helps with:
- 安全漏洞评估
- 兼容性检查
- 系统资产清单管理
服务横幅
服务在建立连接时返回的标识信息,包含服务名称、版本和其他详细信息。横幅信息对安全分析和服务识别非常有用。
常用端口参考
Comprehensive list of commonly used ports, with special focus on email services:
| 端口 | 服务 | 协议 | 说明 | 安全说明 |
|---|---|---|---|---|
| 25 | SMTP | TCP | 简单邮件传输协议——发送邮件 | 明文传输,易被窃听 |
| 110 | POP3 | TCP | 邮局协议第 3 版——接收邮件 | 明文传输,建议使用 SSL 版本 |
| 143 | IMAP | TCP | 互联网消息访问协议——访问邮件 | 明文传输,建议使用 SSL 版本 |
| 465 | SMTPS | TCP | 基于 SSL 的 SMTP——安全发送邮件 | 加密传输,推荐使用 |
| 587 | SMTP-MSA | TCP | 邮件提交代理——提交邮件 | 支持 STARTTLS,现代标准 |
| 993 | IMAPS | TCP | 基于 SSL 的 IMAP——安全访问邮件 | 加密传输,推荐使用 |
| 995 | POP3S | TCP | 基于 SSL 的 POP3——安全接收邮件 | 加密传输,推荐使用 |
| 21 | FTP | TCP | 文件传输协议——文件传输 | 明文传输,存在安全风险 |
| 22 | SSH | TCP | 安全外壳——安全远程登录 | 加密传输,相对安全 |
| 23 | Telnet | TCP | Telnet 协议——远程登录 | 明文传输,极不安全 |
| 53 | DNS | TCP/UDP | 域名系统——域名解析 | 关键服务,需要 DDoS 防护 |
| 80 | HTTP | TCP | 超文本传输协议——Web 服务 | 明文传输,建议使用 HTTPS |
| 443 | HTTPS | TCP | HTTP 安全版——安全 Web 服务 | 加密传输,现代标准 |
| 3389 | RDP | TCP | 远程桌面协议——远程桌面 | 频繁被攻击,需要强认证 |
邮件服务安全建议: 优先使用加密端口(465、587、993、995),避免明文端口(25、110、143)。Configure firewall to restrict access sources, enable strong password policies and multi-factor authentication.
所有端口都显示为被过滤
This usually indicates that the target host has a firewall blocking connections, or the host does not exist.
解决方案:检查目标主机是否在线,并验证防火墙设置。
连接超时
High network latency or slow target host response causes connection timeout.
解决方案:增加超时时间,检查网络连接质量。
DNS 解析失败
Unable to resolve domain name to IP address, possibly due to DNS server issues.
解决方案:直接使用 IP 地址测试,或更换 DNS 服务器。
扫描速度慢
Large-scale port scanning may take considerable time, especially for remote hosts.
解决方案:使用常用端口扫描,或分批进行扫描。
高风险端口
The following ports may pose security risks if unnecessarily open:
防护措施
- 关闭不必要的服务和端口
- 使用防火墙限制访问来源
- 启用强认证机制
- 定期更新系统和软件
- 监控异常连接活动
- 使用 VPN 保护远程访问
安全扫描建议
- 定期进行内网扫描
- 从外部视角测试防火墙有效性
- 记录并分析扫描结果
- 建立基线并监控变化
- 与漏洞扫描工具配合使用
合规要求
Many security standards require regular port scanning:
- PCI DSS——支付卡行业标准
- ISO 27001——信息安全管理
- NIST——网络安全框架
- SOX——《萨班斯-奥克斯利法案》合规
