Free security tool

Port Exposure Fix Generator: Block or Restrict Any Port

Pick the port and your platform, and this free tool writes the firewall commands to block it or limit it to a trusted address range, then shows how to check from outside that the fix worked. It covers Windows, Linux (ufw, firewalld, iptables, nftables), AWS, Azure, Google Cloud and home routers, and it runs entirely in your browser.

  • Free
  • No signup
  • Runs in your browser
  • 9 platforms
  • Copy-paste commands
2. Protocol
4. What do you want?
Enter a port above to see the commands.
Done? Confirm what the internet can still reach with a free scan from the IP vulnerability scanner, or scan a whole range with the network vulnerability scanner.
This tool only writes text for you to review. It never touches your firewall, and nothing you enter leaves your browser. Review every command, test in a non-production environment first, and keep a way back in. Firewall changes can interrupt services and lock you out.

How it works

  1. 1Pick the portType a port or range, or tap a common one like 445 or 3389.
  2. 2Choose your firewallWindows, ufw, firewalld, iptables, nftables, AWS, Azure, Google Cloud or a home router.
  3. 3Copy and verifyRun the commands, then check from outside your network that the port is really closed.

How to use the generator

Choose the port, your platform and whether to block it or limit it to your own addresses, then run the three blocks in order.

  1. See what allows it today. The first block lists the rules and listening services that already mention the port, so you know what you are changing.
  2. Apply the fix. Copy the commands and run them. Each block ends with an undo line.
  3. Check from outside. Run the scan from a network that is not yours, such as a phone hotspot. A scan from inside your network can look fine while the internet still reaches the port.

Block it or allow only a trusted range?

Block ports that nobody outside your network should ever reach, and use a trusted range for ports that your own team needs remotely.

  • Block databases, SMB file sharing, Redis, Elasticsearch, the Docker API and other internal services.
  • Allow only a trusted range for SSH, RDP, WinRM and VNC, and keep that range as small as you can, ideally your VPN or office address.
  • Replace Telnet and FTP with SSH and SFTP, because blocking alone does not give your team a secure way to do the same job.

Ports most often left exposed

These are the ports the generator knows about, with why each one matters and the usual action. Any other port still works: type it in the box.

Port Service Why it matters Usual action
445SMB (Windows file sharing)Wormable exploits and ransomware (EternalBlue, SMBGhost) target exposed SMB.Block from the internet
139NetBIOS session (legacy SMBv1)Legacy SMB over NetBIOS. Block it together with 445.Block from the internet
137NetBIOS name serviceLegacy name resolution used by SMBv1 networks.Block from the internet
138NetBIOS datagram serviceLegacy SMBv1 browsing traffic.Block from the internet
135Windows RPC endpoint mapperExposes Windows remote-management plumbing to the internet.Block from the internet
3389RDP (Remote Desktop)A leading ransomware entry point: brute force and flaws like BlueKeep (CVE-2019-0708).Allow only from a VPN or trusted range
22SSHConstant brute-force target. Use keys and limit who can reach it.Allow only from a trusted range
23TelnetSends logins in cleartext. Replace it with SSH.Block, then replace with SSH
21FTPSends credentials in cleartext. Use SFTP or FTPS instead.Block, then replace with SFTP
5900VNCRemote desktop that is often left with a weak or no password.Allow only from a VPN or trusted range
5985WinRM (HTTP)Remote Windows management over HTTP.Allow only from a trusted range
5986WinRM (HTTPS)Remote Windows management over HTTPS.Allow only from a trusted range
1433Microsoft SQL ServerDatabases should not be reachable from the internet.Block from the internet
3306MySQL / MariaDBDatabases should not be reachable from the internet.Block from the internet
5432PostgreSQLDatabases should not be reachable from the internet.Block from the internet
6379RedisOften runs without authentication; exposed instances are routinely abused.Block from the internet
27017MongoDBExposed databases have repeatedly been wiped or ransomed.Block from the internet
9200ElasticsearchExposed clusters leak data and accept unauthenticated queries.Block from the internet
11211MemcachedData exposure and UDP reflection (DDoS amplification).Block from the internet
2375Docker API (unencrypted)Unauthenticated access to this API means remote control of the host.Block from the internet
161SNMPDefault community strings leak device details and enable amplification.Block from the internet
389LDAPDirectory data and logins; keep internal or use LDAPS through a VPN.Block from the internet
2049NFSFile exports with weak access control by default.Block from the internet
1900SSDP / UPnPRouter exposure and reflection attacks.Block from the internet

For a deeper look at one of them, read our guide to the port 445 vulnerability, or our open ports security risk assessment for how to rank exposed ports in your own environment.

Before you run any firewall command

Make sure you can get back in, because a firewall rule that blocks your own connection can leave you locked out of the machine.

  • Keep a second way in: console access, a cloud serial console, or a second admin session that is already open.
  • Check dependencies before blocking a port on an internal host: file shares, printers, backups and domain controllers can all rely on it.
  • Save the rule if you want it to survive a reboot, because some Linux firewalls keep rules only in memory until you save them.
  • Change one thing at a time and recheck from outside after each change.

Frequently asked questions

How do I block a port in the Windows firewall?Open PowerShell as Administrator and run New-NetFirewallRule with -Direction Inbound, -Protocol TCP, -LocalPort set to your port and -Action Block. Choose Windows in the generator above and it writes the exact command, plus a command to check which rules already mention the port.
What is the difference between blocking a port and allowing only a trusted range?Blocking closes the port to everyone. Allowing only a trusted range keeps it open for your own addresses, such as an office or VPN range, and closes it to the rest of the internet. Use blocking for services nobody outside should reach, such as databases and SMB. Use the trusted range for remote-admin ports such as SSH and RDP.
Will blocking a port break my network?Blocking inbound traffic from the internet rarely breaks anything, because internal traffic does not cross the internet edge. A host-level rule can break internal services that use the port, so check what depends on it first. The generator warns you when a port is one you may be connected through.
Why does my port still show as open after I blocked it?Usually another rule still allows it. Common causes are a second firewall rule, a router port-forwarding rule, a cloud security group or network ACL that you did not change, an IPv6 rule, or scanning from inside your own network. Step 1 in the generator lists the rules that mention the port.
What is the difference between filtered and closed in a port scan?Filtered means a firewall is dropping the traffic, so the scanner gets no answer. Closed means the machine replied that nothing is listening. Both mean the port is not usable from outside. Open means a service answered and the port is still exposed.
Does this tool change my firewall?No. It only writes commands for you to review and run. It runs in your browser and nothing you enter is sent to ScanTitan.

Closed the port? Confirm what the internet can still reach.

Run a free IP scanSee pricing