| actcp | 31766 | TCP | ACT Call Processing Server |
acuxebin | 2301 2381 | TCP | Configuration utility for SA5300 RAID
controller |
ajp12 | 8007 | TCP | ajp12 Connector to HP Apache |
| ajp13 | 8009 | TCP | ajp13 Connector to HP Apache |
albd | 371 | TCP/UDP | ClearCase Server Daemon Also known
as the Atria Location Broker Daemon |
Apache | 80 | | Apache Web Server |
auth_LDAP | 389 | | HP Apache 2.x |
auth_LDAP stunnel | 636 | | HP Apache 2.x |
bftp | 152 | TCP | Background File Transfer Protocol |
| bgp | 179 | TCP | Border Gateway Protocol |
| biff (exec) | 512 | TCP/UDP | Remote Execution |
bootpd | 67-68 | UDP | Bootstrap Protocol Server and Client These
services should function only if the server is a bootp server. If
it is not, disable the service in the /etc/inetd.conf file. |
| c34_main | 8553 | UDP | acceSS7 Inter-Server Messages |
| chargen | 19 | TCP/UDP | Character Generator Archaic port that
can be used as an attack vehicle. It is recommended that you edit
the /etc/inetd.conf file to comment out or disable this service, or use
SAM to disable this service. |
| CIM-XML | 5988 | TCP | CIM-XML (http) WBEM cimserver |
CIM-XML | 5989 | TCP | CIM-XML (https) WBEM cimserver |
Cleansweep | 2301, 2381 | | Cleansweep HTTP and HTTPS traffic,
respectively |
clvm-cfg | 1476 | TCP | HA LVM Configuration |
| comms_high | 8552 | TCP | acceSS7 High Priority Messages |
| comms_normal | 8551 | TCP | acceSS7 Normal Priority Messages |
conference | 531 | TCP | Chat |
| console | 10000 | TCP | MC/System Environment Console Mulitplexor |
courier | 530 | TCP | |
| cvmmon | 2300 | TCP | ClusterView Management Cluster Support |
cvmon | 1686 | UDP | Clusterview cvmon-cvmap Communication |
DAServer | 987 | TCP | SQL Distributed Access |
| Daytime | 13 | TCP/UDP | Report time of day as set on system. Archaic
port that can be used as an attack vehicle. It is recommended that
you edit the /etc/inetd.conf to comment out or disable this service, or use SAM to
disable this service. |
dced/rpcd | 135 | TCP | Distributed Computing Environment (DCE) based
RPC |
desmevt | 6868 | TCP | DE/ Service Monitor, Event Service |
| diagmond | 1508 | TCP | Diagnostic System Manager |
Diameter | 3868 | TCP | Base Diameter protocol |
| Discard | 9
| TCP/UDP | Character Discard Port, also called Sink
or Null Archaic port that can be used as an attack vehicle.
It is recommended that you edit the /etc/inetd.conf file to comment out or disable this service, or use
SAM to disable this service. |
domain | 53 | TCP/UDP | Domain Name Service |
| dtspc | 6112 | TCP | Desktop Subprocess Control Service Used
to run CDE remote actions. To disable this service, comment out
the corresponding line in the /etc/inetd.conf file. |
| Dynamic or Private Ports | 49152-65535 | TCP | Dynamic and Private Ports are used by many
applications for dynamic port assignments. |
| Dynamic or Private Ports | 49152-65535 | UDP | UDP ports in this range are often RPC ports. |
Echo | 7 | TCP/UDP | Line Echo PortArchaic port that can be
used as an attack vehicle. It is recommended that you edit the /etc/inetd.conf file to comment out or disable this service, or use
SAM to disable this service. |
efs | 520 | TCP | Extended File Name Server |
ekshell | 545 | TCP | Kerberos Encrypted Remote Shell -kfall |
| erdb_svr | 35100 | TCP | acceSS7 Statistics Central Database |
| erdb_bck | 35101 | TCP | acceSS7 Statistics Database Backup |
eusrv | 9142 | TCP | eusrv Daemon |
| exec (biff) | 512 | TCP/UDP | Remote Execution |
finger | 79 | TCP | Finger |
ftp | 20 | TCP/UDP | File Transfer Protocol: Data |
ftp | 21 | TCP/UDP | File Transfer Protocol: Control |
| ftp-ftam | 8868 | TCP | FTP->FTAM Gateway |
Gryphon Tomcat | 280, 50000, 50005 | | Gryphon Tomcat services |
grmd | 5999 | TCP | Graphics Resource Manager |
High Availability (HA) Cluster | 5300-5305, 5408 | | ServiceGuard High Availability Cluster
services |
| hacl-cfg | 5302 | TCP/UDP | High Availability (HA) Cluster TCP/UDP Configuration |
| hacl-dlm | 5408 | TCP | High Availability (HA) Distributed Lock Manager |
hacl-gs | 5301 | TCP | High Availability (HA) Cluster General Services |
hacl-hb | 5300 | TCP/UDP | High Availability (HA) Cluster Heartbeat |
hacl-local | 5304 | TCP | High Availability (HA) Cluster Commands |
| hacl-probe | 5303 | TCP/UDP | High Availability (HA) Cluster TCP Probe |
hacl-test | 5305 | TCP | High Availability (HA) Cluster Test |
hcserver | 5710 | TCP | HP Cooperative Services |
HP-AIN services | 6558-6791, 6800, 12345 | TCP | HP OpenCall product family, including
primarily HP-AIN services |
HP Apache | 80, 389, 443, 636, 8005, 8009, 8081, 10000 | | |
hp-clic | 3384 | TCP | Cluster Management Services |
hp-clic | 3384 | UDP | Hardware Management |
hpidsadmin | 2984 | TCP | HP-UX Host Intrusion Detection System (IDS)
Admin |
hpidsagent | 2985 | TCP | HP-UX Host Intrusion Detection System (IDS)
Agent |
hpoms-ci-lstn | 5403 | TCP | SAP Spooler Support |
| hpoms-dps-lstn | 5404 | TCP | SAP Spooler Support |
HP OpenCall | 1527,2206, 6444, 6558-6791, 6800, 8000, 12345 | | HP OpenCall product family, including
primarily HP-AIN services |
HP OpenView | 381-383 | TCP | HP OpenView ports |
HP OpenView Operations | 2531, 7278, 35211 | TCP | HP OpenView Operations ITO Enterprise
Java and Secure Java GUI and Service engine |
| hp-sco | 19410 | TCP/UDP | HP SCO Port Number |
| hp-sca | 19411 | TCP/UDP | HP SCA Port Number |
HP Systems Insight Manager | 280 | | HP Systems Insight Manager HTTP traffic |
HP Systems Insight Manager | 50000 | | HP Systems Insight Manager HTTPS traffic |
HP Systems Insight Manager | 50001, 50002 | | HP Systems Insight Manager HTTPS traffic
for SOAP and SOAP with client authentication, respectively |
HP Telecom | 65000-65536 | | Do not use this port range; incompatible with
third-party connectors to HP Telecom systems. |
wlmpard | 9691 | TCP | HP-UX Workload Manager (WLM) WLM
global arbiter (wlmpard) listens for vPar and nPar client requests. |
http | 80 | TCP/UDP | World Wide Web Hypertext Transfer Protocol;
used by HP-UX Apache |
http | 8081 | TCP | HP-UX Tomcat-based Servlet Engine |
http | 8082 | TCP | HP-UX Tomcat-based Servlet Engine configured
as a proxy server |
| http/https | 10000 | TCP | HP-UX Webmin-based Admin |
https | 443 | TCP | Secure Socket Layer (SSL); used by HP-UX Apache
Web Server |
https | 8443 | TCP | HP-UX Tomcat-based Servlet Engine with SSL |
hostnames | 101 | TCP | NIC Host Name Server |
iasqlsvr | 7489 | TCP | Information Access SQL Server |
ident | 113 | TCP | Authentication Service This
service is used to identify which user owns which services. This
service is unnecessary for general system use. To disable
this service, edit the /etc/inetd.conf file to comment out or disable this service, or use SAM
to disable this service. |
imap | 143 | TCP | IMAP |
insightd | 2301 2381 | TCP | Configuration utility for SA5300 RAID
controller |
instl_bootc | 1068 | UDP | Installation Bootstrap Protocol Client Part
of the Ignite/UX service. You can disable this service in the /etc/inetd.conf file. |
instl_boots | 1067 | UDP | Installation Bootstrap Protocol Server Part
of the Ignite/UX service. You can disable this service in the /etc/inetd.conf file. |
ipsec_mgr | 30453 | | HP-UX IPSec |
isakmp | 500 | TCP/UDP | IPSec Key Management (ISAKMP) |
isee | 1402 | TCP | Event Management Service Listener for HP ISEE Predictive
Support Services It is recommended that access to this
port be restricted to the data center in which the server resides. |
ito-e-gui | 2531 | TCP | ITO Enterprise Java GUI |
ito-e-gui-sec | 35211 | TCP | ITO Enterprise Secure Java GUI |
| Kerberos Services | 88, 543-545, 749-751, 754, 760-761, 2105 | TCP | These ports are used by Kerberos authenticated
service. See the individual Kerberos services below for more details on
the services used by each port. If Kerberos security is
not being used on the system, these ports can be disabled in the /etc/inetd.conf file. |
kerberos | 750 | TCP/UDP | Kerberos (server) -kfall |
kerberos5 | 88 | TCP/UDP | Kerberos 5 kdc |
kerberos-adm | 749 | TCP | Kerberos admin/changepw |
kerberos-cpw | 751 | TCP | Kerberos changepw |
kcweb | 1110, 1188 | | On-Line (OL*) Autostart feature Manage
slots and cards using OL* |
klogin | 543 | TCP | Kerberos rlogin -kfall |
kpasswd | 761 | TCP | Kerberos “passwd” -kfall |
krb5_prop | 754 | TCP | Kerberos slave propagation |
krbupdate | 760 | TCP | Kerberos Registration -kfall |
kshell | 544 | TCP | Kerberos Remote Shell -kfall |
lanmgrx.osB | 5696 | TCP | LAN Manager/X for B.00.00 OfficeShare |
lansrm | 570 | UDP | SRM/UX Server |
LDAP | 389 | TCP | LDAP Directory |
LDAPS | 636 | TCP | SSL LDAP Directory |
link | 87 | TCP | Private Terminal Link |
llbserver | 383 | TCP | HP OpenView Black Box Communication (BBC) llbserver Allows
multiple applications to communicate via a single network communication
configuration. |
lockd | 4045 | TCP/UDP | NFS Lock Manager |
login | 513 | TCP | Remote Login |
mcsemon | 9999 | TCP | MC/System Environment Monitor |
msa | 587 | TCP | Mail Submission Agent (MSA) for sendmail application |
| msql | 1111 | TCP | Mini SQL Database Server |
kwdb | 468 | UDP | KWDB remote kernel debugger through UDP |
kwdbcr | 47002 | TCP | KWDB remote crash dump analyzer |
kwdbd | 47001 | TCP | KWDB communications server for remote kernel debugging |
NCPM | 1591, 1683, 1744 | UDP | NCPM  |  |  |  |  | NOTE: Support for NCPM
will be discontinued in May 2004. |  |  |  |  |
|
| ncpm-ft | 1744 | UDP | NCPM File Transfer  |  |  |  |  | NOTE: Support
for NCPM will be discontinued in May 2004. |  |  |  |  |
|
ncpm-hip | 1683 | UDP | NCPM Host Information Provider  |  |  |  |  | NOTE: Support for NCPM will be discontinued in May 2004. |  |  |  |  |
|
| ncpm-pm | 1591 | UDP | NCPM Policy Manager  |  |  |  |  | NOTE: Support
for NCPM will be discontinued in May 2004. |  |  |  |  |
|
netbios_ns | 137 | TCP/UDP | NetBIOS Name Service The CIFS
server uses this port. See the CIFS Server documentation referred
to in Chapter 3 “Additional Information”for information
about configuring security for this port. |
netbios_dgm | 138 | TCP/UDP | NetBIOS Datagram Service The
CIFS server uses this port. See the CIFS Server documentation for
information about configuring security for this port. |
netbios_ssn | 139 | TCP/UDP | NetBIOS Session Service The CIFS server
uses this port. See the CIFS Server documentation in Chapter 3 “Additional Information” for information about configuring
security for this port. |
netdist | 2106 | TCP | Update (1m) Network Distribution Service |
netnews | 532 | TCP | Read News |
| netview | 4010 | TCP | Netview Management Used for communication
with Netview event communications. |
| netview | 4020 | TCP | Netview Management Used for communication
with Netview event communications. |
netwall | 533 | UDP | Emergency Broadcasting |
Network Services | 1536-1543, 1570, 2560-2564 | | Used by Network Services on HP3000 systems. |
nfsd | 2049 | TCP/UDP | NFS Remote File System |
nfsd-keepalive | 1110 | UDP | Client Status Information |
| nfsd-status | 1110 | TCP | Cluster Status Information |
nft | 1536 | TCP | NS Network File Transfer |
| nntp | 119 | TCP | Network News Transfer Protocol Not
commonly found on HP-UX systems. |
ntalk | 518 | UDP | New Talk, Conversation You can disable
this service in the /etc/inetd.conf file. |
ObS | 30999 | TCP | Advanced Problem Consolidator ObjectServer
(ObS) Foundation component of OpenView used for data modeling
and storage. |
| omni | 5555 | TCP | OMNIBACK-II Data Protector Cell |
opcsvcterm | 7278 | TCP | Service Engine Remote Access HP OpenView |
Oracle | 1748, 1754, 1808-1809 | TCP | Oracle Applications and Processes Ports
used by Oracle database applications and processes. See
individual oracle processes and application services for more information. |
| oracle-em1 | 1748 | TCP | Oracle Process Part of the Oracle
snmp process, configured for the Oracle Enterprise Manager. |
oracle-em2 | 1754 | TCP | Oracle Process Part of the Oracle
snmp process, configured for the Oracle Enterprise Manager. |
oracle-vp1 | 1809 | TCP | Oracle Used for communication between
Performance Manager and Agent or Capacity Planner and Agent. |
| oracle-vp2 | 1808 | TCP | Oracle Used for communication between
Performance Manager and Agent or Capacity Planner and Agent. |
| p7_c33upd | 8545 | TCP | TSD acceSS7 Configuration Update RPC Server |
| p7_c33 | 8546 | TCP | TSD acceSS7 Configuration RPC Server |
| p7_c32 | 8547 | TCP | TSD acceSS7 Communications Status RPC
Server |
| p7_c35 | 8548 | TCP | TSD acceSS7 Communications Configuration RPC
Server |
| p7_g06 | 8549 | TCP | TSD acceSS7 Application Version Registration
RPC Server |
| p7_e30 | 8550 | TCP | TSD acceSS7 Event Manager RPC Server |
pdclientd | 6874 | TCP | Palladium Print Client Daemon |
pdeventd | 6875 | TCP | Palladium Print Event Daemon |
pdweb | 1110, 1188 | | On-Line Add or Replace(OL*) Autostart
feature Manage slots and cards using OL* |
PeerServer | 6606 | TCP | Advanced Problem Consolidator PeerServer Extensible
peer-to-peer networking server that allows for registration of different
components that want to communicate as peers within a network. |
PeerServer (local) | 6605 | TCP | Advanced Problem Consolidator PeerServer Used
for PeerServer interprocess communications. |
pmlockd | 1889 | TCP/UDP | SynerVision Locking Daemon |
pop | 109 | TCP | Post Office Protocol Version 2 |
pop3 | 110 | TCP | Post Office Protocol Version 3 |
portmap | 111 | TCP/UDP | SUN Remote Procedure Call
|
printer | 515 | TCP | Remote Print Spooling If the server
is not used as a print server, disable this service in the /etc/inetd.conf file. |
prm_rmconf | 9610 | TCP | Process Resource Manager Remote Configuration
Daemon |
psmond | 1788 | TCP/UDP | Predictive Monitor |
| pvalarm | 383 | TCP | PerfView Alarm Management See Port
382 for more information. |
| pvserver | 382 | TCP | PerfView Server |
qotd | 17 | TCP/UDP | Quote of the Day Archaic port that
can be used as an attack vehicle. It is recommended that you edit
the /etc/inetd.conf file to comment out or disable this service, or use SAM
to disable this service. |
r4-sna-cs | 5707 | TCP | SNA Client/Server (up to Release 4.1) obsolete
on HP-UX 11i v2 |
r4-sna-ft | 5709 | TCP | SNA File Transfer (up to Release 4.1) obsolete
on HP-UX 11i v2 |
| radacct | 1813 | UDP | RADIUS Protocol Used by the AAA RADIUS
Server. See Chapter 3 “Additional Information” for
references to AAA RADIUS documentation. |
radius | 1812 | UDP | RADIUS Protocol Used by the AAA RADIUS
Server. See Chapter 3 “Additional Information” for
references to AAA RADIUS documentation. |
| recserv | 7815 | TCP | SharedX Receiver Service Used to share
an X-Windows display from another system. You can disable this service
in the /etc/inetd.conf file. |
| Registered Ports | 1024-49151 | n/a | Registered Ports are listed by the IANA.
On most systems Registered Ports can be used by ordinary user processes
or programs executed by ordinary users. Registered Ports are used
in TCP (RFC793) to name the ends of logical connections that carry
on long conversations. To provide services to unknown callers, a
registered service contact port is defined. This list specifies
the ports used by services as contact ports. |
registrar | 1712 | TCP/UDP | Resource Monitoring Service Part of
the resource monitoring subsystem. |
remotefs | 556 | TCP | Brunhoff Remote Filesystem |
rfa | 4672 | TCP | NS Remote File Access |
RIPng | 521 | TCP/UDP | Route Information Protocol Next Generation RIPng
is used with IPv6 only. |
| rje | 5 | TCP/UDP | Remote Job Entry Service Not
common on HP-UX. You can edit the /etc/inetd.conf file to comment out or disable this service. |
rje | 77 | TCP | Private Remote Job Entry Service |
| rlb | 1260 | TCP | Remote Loopback Diagnostic |
rlp | 39 | UDP | Resource Location Protocol |
route | 520 | UDP | Routing Information Protocol |
ideafarm-catch | 903 | UDP | IDEAFARM-CATCH |
rpcd | 135 | TCP | Distributed Computing Environment (DCE) based
RPC |
rpcbind | 111 | | rpcbind |
SA5300 RAID controller | 2301 2381 | TCP | Configuration and Management utilities
for the SA5300 RAID controller |
| samd | 3275 | TCP | System Administration Manager Daemon |
SAP | 3200, 3300, 3600 | TCP | SAP software assigned ports. |
sapdp00 | 3200 | TCP | SAP SAP software assigned port. |
sapgw00 | 3300 | TCP | SAP SAP software assigned port. |
| sapmsES1 | 3600 | TCP | SAP SAP software assigned port. |
SCM | 280, 50000, 50005 | TCP | ServiceControl Manager 3.0 Used by
ServiceControl Manager 3.0 for non-secure http requests. |
| ServiceGuard | 5300-5305, 5408 | | ServiceGuard High Availability Cluster
services |
sftp | 115 | TCP | Secure File Transfer Protocol |
shell | 514 | TCP | Remote Command, No Password Used |
sip | 5060 | TCP | Session Initialization Port ISEE Web
Configuration Port for HP ISEE Predictive Support Services. |
SMB | 445 | TCP | CIFS Internal Service |
smtp | 25 | TCP | Simple Mail Transfer Protocol |
SNA | 1553, 5707-5709 | TCP/UDP | SNAplus2 |
sna-cs | 1553 | TCP/UDP | SNAplus Client/Server |
SNAplus | 5708 | UDP | SNA Logical Network (up to Release 4.1) obsolete
for HP-UX 11i v2 |
snmp | 161 | UDP | Simple Network Management Protocol
|
| snmpdm | 7161 | TCP | Simple Network Manage Protocol (SNMP) Daemon See
port 161 for more information. |
snmptrap | 162 | TCP/UDP | Simple Network Management Protocol Trap Handler See
Port 161 for more information. |
spc | 6111 | TCP | Sub-Process Control |
SrpSiteDaemon | 6178 | TCP | acceSS7 Statistics Remote Site Query Daemon |
SrpCentralDaemon | 6179 | TCP | acceSS7 Statistics Central Server Query Daemon |
ssh | 22 | TCP | HP-UX Secure Shell SSH uses this port
by default. An administrator can configure SSH to use a different
port. |
SSL | 443 | TCP | HP Apache Secure Socket Layer (SSL) |
sunrpc | 111 | TCP/UDP | SUN Remote Procedure Call |
supdup | 95 | TCP | |
| swagentd | 2121 | TCP/UDP | HP Software Distributor Daemon Used
for communication between systems for software installation, listing,
or other sw commands. |
| swat | 901 | TCP | SAMBA Web-based Admin Tool Used by
the HP CIFS product (equivalent to the open source SAMBA product).
If CIFS is not being used, this service can be disabled in the /etc/inetd.conf file. |
| syslogd | 514 | UDP | Network System Logging |
systat | 11 | TCP | Active Users, also called users |
talk | 517 | UDP | Talk, Conversation |
| tcpmux | 1 | TCP | TCP port service multiplexer Not common
on HP-UX. You can edit the /etc/inetd.conf file to comment out or disable this service. |
tempo | 526 | TCP | New Date |
tftpd | 69 | UDP | Trivial File Transfer Protocol Found
on systems that have Ignite/UX installed. This service should function
only if the host is being used as a tftp server. If you want to
disable this service, edit the /etc/inetd.conf file. |
time | 37 | TCP/UDP | Time Responds to a time request. If
you use this service, it is recommended that you convert to the
Network Time Protocol and use a secure server. If you
want to disable this service, edit the /etc/inetd.conf file to comment out or disable this service, or use
SAM to disable this service. |
timed | 525 | UDP | Remote Clock Synchronization |
TIPs | 6604 | TCP | Advanced Problem Consolidator TIPs Server Server-side
component for Troubleshooting Insight Packages (TIPs). |
| tnlsnr | 1521 | TCP | Oracle TNSLSNR for HP-UX Part of
the Oracle database system. It is recommended that you secure this
service with a password. |
Tomcat | 8005, 8008, 8009, 8081 | | Tomcat services |
| Tomcat -based Servlet Engine | 8081 | TCP | HP-UX Tomcat-based Servlet Engine (HTTP 1.0) |
Tomcat HTTP Connector | 8080 | | HTTP Connector |
Tomcat Warp Connector | 8008 | | Tomcat Warp Connector |
traceroute | 33434 | UDP | Traceroute |
tsap | 102 | TCP | ISO TSAP (part of ISODE). Used by OTS/9000
when RFC1006 configuration is enabled. |
TSD acceSS7 | 8545-8550 | TCP | |
uucp | 540 | TCP | uucp Daemon |
uucp-path | 117 | TCP | UUCP Path Service |
| veesm | 4789 | TCP | HP VEE Service Manager |
Webmin | 10000 | | HP Apache Webmin configuration tool |
| Well-known ports | 0-1023 | n/a | Well Known Ports are assigned by the
IANA. These ports can only be used by system or root processes,
or by applications executed by privileged users. |
| who | 513 | UDP | Remote Who and Uptime |
whois | 43 | TCP | Who Is, also called nicname |
wlmcomd | 9692 | TCP | HP-UX Workload Manager (WLM) daemon WLM
listens for remote client requests. |
wlmpard | 9691 | TCP | HP-UX Workload Manager (WLM) WLM
global arbiter (wlmpard) listens for vPar and nPar client requests. |
| X10_LI | 5800 + display number | | X-Windows (obsolete) The X10_LI server
for each display listens on this port range. Do not associate other
services with this port range. |
| X10_MI | 5900 + display number | | X-Windows (obsolete) The X10_MI server
for each display listens on this port range. Do not associate other
services with this port range. |
| X11 | 6000 + display number | TCP/UDP | X-Windows The X11 server for each
display listens on this port range. Do not associate other services
with this port range. See ports in the 7000 range for
more information about ports used by X-Windows. |
| X11 | 7000 | TCP | X-Windows The X11 font server listens
on this port. Do not associate other services with this port. See
port 6000 for more information about X-Windows ports. |
| xdmcp | 177 | UDP | X-Windows Display Manager Control Protocol You
can edit the /etc/dt/config/Xaccess file to allow or deny xdmcp access to the appropriate
hosts. |
xntpd | 123 | UDP | Network Time Protocol Establishes
relationships between servers. This service is not normally configured
on HP-UX servers. |