Port Exposure Fix Generator: Block or Restrict Any Port
Pick the port and your platform, and this free tool writes the firewall commands to block it or limit it to a trusted address range, then shows how to check from outside that the fix worked. It covers Windows, Linux (ufw, firewalld, iptables, nftables), AWS, Azure, Google Cloud and home routers, and it runs entirely in your browser.
- Free
- No signup
- Runs in your browser
- 9 platforms
- Copy-paste commands
How it works
- 1Pick the portType a port or range, or tap a common one like 445 or 3389.
- 2Choose your firewallWindows, ufw, firewalld, iptables, nftables, AWS, Azure, Google Cloud or a home router.
- 3Copy and verifyRun the commands, then check from outside your network that the port is really closed.
How to use the generator
Choose the port, your platform and whether to block it or limit it to your own addresses, then run the three blocks in order.
- See what allows it today. The first block lists the rules and listening services that already mention the port, so you know what you are changing.
- Apply the fix. Copy the commands and run them. Each block ends with an undo line.
- Check from outside. Run the scan from a network that is not yours, such as a phone hotspot. A scan from inside your network can look fine while the internet still reaches the port.
Block it or allow only a trusted range?
Block ports that nobody outside your network should ever reach, and use a trusted range for ports that your own team needs remotely.
- Block databases, SMB file sharing, Redis, Elasticsearch, the Docker API and other internal services.
- Allow only a trusted range for SSH, RDP, WinRM and VNC, and keep that range as small as you can, ideally your VPN or office address.
- Replace Telnet and FTP with SSH and SFTP, because blocking alone does not give your team a secure way to do the same job.
Ports most often left exposed
These are the ports the generator knows about, with why each one matters and the usual action. Any other port still works: type it in the box.
| Port | Service | Why it matters | Usual action |
|---|---|---|---|
| 445 | SMB (Windows file sharing) | Wormable exploits and ransomware (EternalBlue, SMBGhost) target exposed SMB. | Block from the internet |
| 139 | NetBIOS session (legacy SMBv1) | Legacy SMB over NetBIOS. Block it together with 445. | Block from the internet |
| 137 | NetBIOS name service | Legacy name resolution used by SMBv1 networks. | Block from the internet |
| 138 | NetBIOS datagram service | Legacy SMBv1 browsing traffic. | Block from the internet |
| 135 | Windows RPC endpoint mapper | Exposes Windows remote-management plumbing to the internet. | Block from the internet |
| 3389 | RDP (Remote Desktop) | A leading ransomware entry point: brute force and flaws like BlueKeep (CVE-2019-0708). | Allow only from a VPN or trusted range |
| 22 | SSH | Constant brute-force target. Use keys and limit who can reach it. | Allow only from a trusted range |
| 23 | Telnet | Sends logins in cleartext. Replace it with SSH. | Block, then replace with SSH |
| 21 | FTP | Sends credentials in cleartext. Use SFTP or FTPS instead. | Block, then replace with SFTP |
| 5900 | VNC | Remote desktop that is often left with a weak or no password. | Allow only from a VPN or trusted range |
| 5985 | WinRM (HTTP) | Remote Windows management over HTTP. | Allow only from a trusted range |
| 5986 | WinRM (HTTPS) | Remote Windows management over HTTPS. | Allow only from a trusted range |
| 1433 | Microsoft SQL Server | Databases should not be reachable from the internet. | Block from the internet |
| 3306 | MySQL / MariaDB | Databases should not be reachable from the internet. | Block from the internet |
| 5432 | PostgreSQL | Databases should not be reachable from the internet. | Block from the internet |
| 6379 | Redis | Often runs without authentication; exposed instances are routinely abused. | Block from the internet |
| 27017 | MongoDB | Exposed databases have repeatedly been wiped or ransomed. | Block from the internet |
| 9200 | Elasticsearch | Exposed clusters leak data and accept unauthenticated queries. | Block from the internet |
| 11211 | Memcached | Data exposure and UDP reflection (DDoS amplification). | Block from the internet |
| 2375 | Docker API (unencrypted) | Unauthenticated access to this API means remote control of the host. | Block from the internet |
| 161 | SNMP | Default community strings leak device details and enable amplification. | Block from the internet |
| 389 | LDAP | Directory data and logins; keep internal or use LDAPS through a VPN. | Block from the internet |
| 2049 | NFS | File exports with weak access control by default. | Block from the internet |
| 1900 | SSDP / UPnP | Router exposure and reflection attacks. | Block from the internet |
For a deeper look at one of them, read our guide to the port 445 vulnerability, or our open ports security risk assessment for how to rank exposed ports in your own environment.
Before you run any firewall command
Make sure you can get back in, because a firewall rule that blocks your own connection can leave you locked out of the machine.
- Keep a second way in: console access, a cloud serial console, or a second admin session that is already open.
- Check dependencies before blocking a port on an internal host: file shares, printers, backups and domain controllers can all rely on it.
- Save the rule if you want it to survive a reboot, because some Linux firewalls keep rules only in memory until you save them.
- Change one thing at a time and recheck from outside after each change.
Frequently asked questions
How do I block a port in the Windows firewall?
Open PowerShell as Administrator and run New-NetFirewallRule with -Direction Inbound, -Protocol TCP, -LocalPort set to your port and -Action Block. Choose Windows in the generator above and it writes the exact command, plus a command to check which rules already mention the port.What is the difference between blocking a port and allowing only a trusted range?
Blocking closes the port to everyone. Allowing only a trusted range keeps it open for your own addresses, such as an office or VPN range, and closes it to the rest of the internet. Use blocking for services nobody outside should reach, such as databases and SMB. Use the trusted range for remote-admin ports such as SSH and RDP.Will blocking a port break my network?
Blocking inbound traffic from the internet rarely breaks anything, because internal traffic does not cross the internet edge. A host-level rule can break internal services that use the port, so check what depends on it first. The generator warns you when a port is one you may be connected through.Why does my port still show as open after I blocked it?
Usually another rule still allows it. Common causes are a second firewall rule, a router port-forwarding rule, a cloud security group or network ACL that you did not change, an IPv6 rule, or scanning from inside your own network. Step 1 in the generator lists the rules that mention the port.What is the difference between filtered and closed in a port scan?
Filtered means a firewall is dropping the traffic, so the scanner gets no answer. Closed means the machine replied that nothing is listening. Both mean the port is not usable from outside. Open means a service answered and the port is still exposed.Does this tool change my firewall?
No. It only writes commands for you to review and run. It runs in your browser and nothing you enter is sent to ScanTitan.Closed the port? Confirm what the internet can still reach.
Run a free IP scanSee pricing