MFormations
Modern Network Engineering

Chapitre 23

23 - Annexes Techniques

23 - Annexes Techniques

Cours 23 : Annexes Techniques

Introduction

Ce chapitre rassemble les annexes essentielles pour l'ingénieur réseau : glossaire de 200+ termes, cheat sheets imprimables, index des RFCs, et tableau des ports well-known.


Partie 1 : Glossaire (200+ Termes)

A

  • AAA : Authentication, Authorization, Accounting - cadre de gestion des accès
  • ACL : Access Control List - liste de règles filtrant le trafic
  • AD : Administrative Distance - mesure de fiabilité d'une source de route
  • Anycast : adresse attribuée à plusieurs interfaces, routée vers la plus proche
  • API : Application Programming Interface - interface de programmation
  • ARP : Address Resolution Protocol - résolution IP -> MAC
  • AS : Autonomous System - domaine de routage sous une administration unique
  • ASIC : Application-Specific Integrated Circuit - circuit dédié au forwarding
  • ASN : Autonomous System Number - identifiant unique d'un AS
  • ATM : Asynchronous Transfer Mode - technologie de commutation de cellules
  • AWS : Amazon Web Services - cloud provider

B

  • BDR : Backup Designated Router - backup OSPF pour réseau multi-accès
  • BGP : Border Gateway Protocol - protocole de routage inter-domaine
  • BPDU : Bridge Protocol Data Unit - trame STP
  • BUM : Broadcast, Unknown Unicast, Multicast - trafic de flooding
  • Byte : 8 bits, unité de mesure de données

C

  • CASB : Cloud Access Security Broker - sécurité cloud
  • CCNA : Cisco Certified Network Associate - certification Cisco
  • CDN : Content Delivery Network - réseau de distribution de contenu
  • CIDR : Classless Inter-Domain Routing - notation de masque (ex: /24)
  • Cilium : plugin CNI basé sur eBPF pour Kubernetes
  • CIR : Committed Information Rate - débit garanti
  • CLI : Command Line Interface - interface en ligne de commande
  • CMS : Content Management System - système de gestion de contenu
  • CNI : Container Network Interface - interface réseau pour conteneurs
  • CNCF : Cloud Native Computing Foundation - fondation cloud-native
  • CPU : Central Processing Unit - unité centrale de traitement
  • CRC : Cyclic Redundancy Check - détection d'erreurs
  • CSU/DSU : Channel Service Unit/Data Service Unit - interface WAN

D

  • DDoS : Distributed Denial of Service - attaque par déni de service distribué
  • DHCP : Dynamic Host Configuration Protocol - configuration IP automatique
  • DLCI : Data Link Connection Identifier - identifiant Frame Relay
  • DMZ : Demilitarized Zone - zone démilitarisée réseau
  • DNAT : Destination NAT - traduction d'adresse destination
  • DNS : Domain Name System - résolution de noms
  • DNSSEC : DNS Security Extensions - sécurisation des réponses DNS
  • DoS : Denial of Service - attaque par déni de service
  • DR : Designated Router - routeur élu OSPF
  • DSCP : Differentiated Services Code Point - marquage QoS
  • Dual Stack : implémentation simultanée IPv4 et IPv6

E

  • E2E : End-to-End - de bout en bout
  • EBC : Explicit Congestion Notification - notification de congestion
  • ECMP : Equal Cost Multi Path - répartition sur chemins égaux
  • eBPF : Extended Berkeley Packet Filter - programmation du noyau Linux
  • EGP : Exterior Gateway Protocol - protocole de passerelle externe
  • EIGRP : Enhanced Interior Gateway Routing Protocol - protocole Cisco
  • ES : Edge Switch - commutateur de bordure
  • EVPN : Ethernet VPN - VPN Ethernet avec contrôle BGP
  • Ethernet : technologie LAN IEEE 802.3
  • EVE-NG : Emulated Virtual Environment - plateforme de lab réseau

F

  • FCS : Frame Check Sequence - séquence de contrôle de trame
  • FIB : Forwarding Information Base - table de forwarding
  • FIN : Finish - flag TCP de terminaison
  • FQDN : Fully Qualified Domain Name - nom de domaine complet
  • FRR : Fast Reroute - reroutage rapide MPLS
  • FRRouting : Free Range Routing - suite de routage open-source
  • FTP : File Transfer Protocol - protocole de transfert de fichiers
  • FW : Firewall - pare-feu
  • FCoE : Fibre Channel over Ethernet - stockage sur Ethernet

G

  • GMPLS : Generalized MPLS - MPLS généralisé
  • gNMI : gRPC Network Management Interface - interface de gestion gRPC
  • GNS3 : Graphical Network Simulator - simulateur réseau graphique
  • gRPC : gRPC Remote Procedure Calls - framework RPC moderne
  • GRE : Generic Routing Encapsulation - tunnel générique
  • GUI : Graphical User Interface - interface graphique

H

  • HDLC : High-Level Data Link Control - protocole liaison
  • HOL : Head-of-Line blocking - blocage de tête de ligne
  • HSRP : Hot Standby Router Protocol - protocole de redondance Cisco
  • HTTP : Hypertext Transfer Protocol - protocole web
  • HTTPS : HTTP over TLS - HTTP sécurisé
  • Hub : répéteur multiport (couche 1)

I

  • IANA : Internet Assigned Numbers Authority - autorité d'attribution
  • ICMP : Internet Control Message Protocol - messages de contrôle
  • IDS : Intrusion Detection System - détection d'intrusion
  • IEEE : Institute of Electrical and Electronics Engineers - organisme de standardisation
  • IETF : Internet Engineering Task Force - groupe de standardisation
  • IGP : Interior Gateway Protocol - protocole de routage interne
  • IKE : Internet Key Exchange - échange de clés IPsec
  • IMAP : Internet Message Access Protocol - accès aux emails
  • In-band : gestion via le réseau de production
  • Ingress : trafic entrant
  • IoT : Internet of Things - internet des objets
  • IP : Internet Protocol - protocole réseau
  • IPAM : IP Address Management - gestion des adresses IP
  • IPS : Intrusion Prevention System - prévention d'intrusion
  • IPsec : IP Security - sécurité IP
  • IPv4 : Internet Protocol version 4 - protocole IP version 4
  • IPv6 : Internet Protocol version 6 - protocole IP version 6
  • IS-IS : Intermediate System to Intermediate System - protocole IGP
  • ISL : Inter-Switch Link - trunking Cisco propriétaire
  • ISO : International Organization for Standardization - normalisation
  • ISP : Internet Service Provider - fournisseur d'accès Internet
  • ISR : Integrated Services Router - routeur Cisco services intégrés
  • ITU : International Telecommunication Union - union des télécommunications
  • I/O : Input/Output - entrée/sortie

J

  • Jitter : variation de la latence
  • Jumbo Frame : trame > 1500 octets
  • JunOS : système d'exploitation Juniper

K

  • K8s : Kubernetes - orchestration de conteneurs
  • Keepalive : message pour maintenir une connexion active
  • Kernel : noyau du système d'exploitation
  • Kubernetes : plateforme d'orchestration de conteneurs

L

  • LACP : Link Aggregation Control Protocol - agrégation de liens
  • LAN : Local Area Network - réseau local
  • LDP : Label Distribution Protocol - distribution de labels MPLS
  • Leaf : commutateur d'accès dans une topologie spine-leaf
  • LSA : Link State Advertisement - annonce d'état de lien OSPF
  • LSDB : Link State Database - base d'états de liens OSPF
  • LSP : Label Switched Path - chemin à commutation d'étiquettes
  • LSR : Label Switch Router - routeur à commutation d'étiquettes
  • LTE : Long Term Evolution - standard 4G
  • L2 / L3 / L4 / L7 : couches du modèle OSI

M

  • MAC : Media Access Control - contrôle d'accès au support
  • MAN : Metropolitan Area Network - réseau métropolitain
  • MC-LAG : Multi-Chassis Link Aggregation - agrégation multi-châssis
  • MD5 : Message Digest 5 - fonction de hachage
  • MED : Multi-Exit Discriminator - attribut BGP
  • MIB : Management Information Base - base d'informations SNMP
  • MLAG : Multi-Link Aggregation Group - agrégation multi-châssis
  • MLD : Multicast Listener Discovery - découverte d'écouteurs multicast
  • MP-BGP : MultiProtocol BGP - BGP multi-protocole
  • MPLS : MultiProtocol Label Switching - commutation d'étiquettes
  • MSS : Maximum Segment Size - taille maximale de segment TCP
  • MSTP : Multiple Spanning Tree Protocol - STP multiple
  • MTU : Maximum Transmission Unit - unité maximale de transmission
  • mTLS : mutual TLS - TLS mutuel
  • Multicast : communication un-à-plusieurs
  • MVPN : Multicast VPN - VPN multicast

N

  • NAC : Network Access Control - contrôle d'accès réseau
  • NAT : Network Address Translation - traduction d'adresses réseau
  • NDP : Neighbor Discovery Protocol - découverte de voisins IPv6
  • NetFlow : protocole de monitoring de flux (Cisco)
  • NETCONF : Network Configuration Protocol - configuration réseau
  • NFV : Network Functions Virtualization - virtualisation des fonctions réseau
  • NGFW : Next-Generation Firewall - pare-feu nouvelle génération
  • NIC : Network Interface Card - carte réseau
  • NMS : Network Management System - système de gestion réseau
  • NSX : VMware NSX - plateforme de virtualisation réseau VMware
  • NTF : Network Function Transformation - transformation des fonctions réseau
  • nftables : successeur de iptables
  • NTP : Network Time Protocol - synchronisation temporelle

O

  • OAM : Operations, Administration, and Maintenance - opérations réseau
  • OC : Optical Carrier - niveau de fibre optique
  • ODF : Optical Distribution Frame - répartiteur optique
  • OID : Object Identifier - identifiant SNMP
  • ONAP : Open Network Automation Platform - automation réseau open-source
  • OpenFlow : protocole SDN
  • OSI : Open Systems Interconnection - modèle de référence (7 couches)
  • OSPF : Open Shortest Path First - protocole IGP link-state
  • Out-of-band : gestion via canal séparé (console, management)

P

  • P : Provider router - routeur fournisseur MPLS
  • P2P : Point-to-Point - point-à-point
  • PAT : Port Address Translation - traduction avec port
  • PBR : Policy-Based Routing - routage basé sur des politiques
  • PCEP : Path Computation Element Protocol - protocole PCE
  • PDU : Protocol Data Unit - unité de données de protocole
  • PE : Provider Edge - routeur de bordure fournisseur
  • PIM : Protocol Independent Multicast - multicast
  • POP : Point of Presence - point de présence
  • PPP : Point-to-Point Protocol - protocole point-à-point
  • PPPoE : PPP over Ethernet - PPP sur Ethernet
  • PRTG : Paessler Router Traffic Grapher - outil de monitoring
  • PSH : Push - flag TCP
  • PSTN : Public Switched Telephone Network - réseau téléphonique
  • PVST : Per-VLAN Spanning Tree - STP par VLAN
  • PBR : Policy-Based Routing - routage basé politiques

Q

  • Q-in-Q : 802.1Q tunneling - double encapsulation VLAN
  • QoS : Quality of Service - qualité de service
  • QUIC : Quick UDP Internet Connections - protocole transport moderne
  • Quagga : ancienne suite de routage open-source (remplacé par FRR)

R

  • RADIUS : Remote Authentication Dial-In User Service - authentification
  • RAM : Random Access Memory - mémoire vive
  • RBAC : Role-Based Access Control - contrôle d'accès basé rôles
  • RCP : Remote Copy Protocol - copie à distance
  • RD : Route Distinguisher - distinguateur de route (MPLS)
  • RESTCONF : REST Configuration Protocol - configuration REST
  • RFC : Request for Comments - documents de standardisation Internet
  • RIB : Routing Information Base - base d'informations de routage
  • RIP : Routing Information Protocol - protocole IGP distance-vector
  • RMON : Remote Network Monitoring - monitoring à distance
  • RP : Rendezvous Point - point de rendez-vous PIM
  • RPKI : Resource Public Key Infrastructure - infrastructure à clé publique
  • RR : Route Reflector - réflecteur de routes BGP
  • RST : Reset - flag TCP de réinitialisation
  • RSTP : Rapid Spanning Tree Protocol - STP rapide (802.1w)
  • RT : Route Target - cible de route (MPLS)
  • RTO : Recovery Time Objective - objectif de temps de récupération
  • RTP : Real-time Transport Protocol - transport temps réel
  • RTT : Round Trip Time - temps aller-retour

S

  • SA : Security Association - association de sécurité IPsec
  • SASE : Secure Access Service Edge - convergence réseau/sécurité
  • SD-Access : Software-Defined Access - accès défini par logiciel (Cisco)
  • SD-WAN : Software-Defined Wide Area Network - WAN défini par logiciel
  • SDN : Software-Defined Networking - réseau défini par logiciel
  • SFP : Small Form-factor Pluggable - module interface amovible
  • SHA : Secure Hash Algorithm - algorithme de hachage
  • SID : Segment Identifier - identifiant de segment SR
  • SLAAC : Stateless Address Autoconfiguration - auto-configuration IPv6
  • SMTP : Simple Mail Transfer Protocol - transfert de courrier
  • SNAT : Source NAT - traduction d'adresse source
  • SNMP : Simple Network Management Protocol - gestion réseau
  • SNR : Signal-to-Noise Ratio - rapport signal/bruit
  • SONET : Synchronous Optical Networking - réseau optique synchrone
  • SPAN : Switched Port Analyzer - analyse de port
  • SPF : Shortest Path First - algorithme de plus court chemin (Dijkstra)
  • SPF : Sender Policy Framework - vérification d'expéditeur email
  • Spine : commutateur coeur dans une topologie spine-leaf
  • SR : Segment Routing - routage par segments
  • SRv6 : Segment Routing over IPv6
  • SSH : Secure Shell - shell sécurisé
  • SSL : Secure Sockets Layer - ancien nom de TLS
  • STP : Spanning Tree Protocol - arbre recouvrant (802.1D)
  • SWG : Secure Web Gateway - passerelle web sécurisée
  • SYN : Synchronize - flag TCP de synchronisation

T

  • TACACS+ : Terminal Access Controller Access-Control System Plus - AAA
  • CAM : Content-Addressable Memory - mémoire à contenu adressable
  • TCAM : Ternary Content-Addressable Memory - mémoire ternaire
  • TCP : Transmission Control Protocol - protocole de contrôle de transmission
  • TE : Traffic Engineering - ingénierie de trafic
  • TFTP : Trivial File Transfer Protocol - transfert de fichiers simple
  • TLS : Transport Layer Security - sécurité de la couche transport
  • TLV : Type-Length-Value - format d'encodage
  • ToR : Top of Rack - commutateur en haut de baie
  • TTL : Time To Live - durée de vie
  • TLS : Transport Layer Security - protocole de sécurité transport

U

  • UDP : User Datagram Protocol - protocole de datagramme utilisateur
  • UIC : Unrestricted Input Control - contrôle d'entrée
  • UM : Unified Management - gestion unifiée
  • Unicast : communication un-à-un
  • URL : Uniform Resource Locator - localisateur de ressource
  • UTM : Unified Threat Management - gestion unifiée des menaces

V

  • VLAN : Virtual Local Area Network - réseau local virtuel
  • VLSM : Variable Length Subnet Mask - masque de longueur variable
  • VM : Virtual Machine - machine virtuelle
  • VNI : VXLAN Network Identifier - identifiant de réseau VXLAN
  • VoIP : Voice over IP - voix sur IP
  • VPC : Virtual Private Cloud - cloud privé virtuel
  • VPN : Virtual Private Network - réseau privé virtuel
  • VRF : Virtual Routing and Forwarding - routage et forwarding virtuels
  • VRRP : Virtual Router Redundancy Protocol - redondance de passerelle
  • VSS : Virtual Switching System - système de commutation virtuel (Cisco)
  • VTEP : VXLAN Tunnel Endpoint - extrémité de tunnel VXLAN
  • VTP : VLAN Trunking Protocol - protocole de gestion VLAN
  • VXLAN : Virtual eXtensible LAN - LAN extensible virtuel

W

  • WAN : Wide Area Network - réseau étendu
  • WAP : Wireless Access Point - point d'accès sans-fil
  • WCCP : Web Cache Communication Protocol - protocole de cache web
  • WDM : Wavelength Division Multiplexing - multiplexage en longueur d'onde
  • Wi-Fi : Wireless Fidelity - réseau sans-fil IEEE 802.11
  • WIPS : Wireless Intrusion Prevention System - prévention d'intrusion Wi-Fi
  • Wireshark : analyseur de paquets
  • WLAN : Wireless Local Area Network - réseau local sans-fil
  • WLC : Wireless LAN Controller - contrôleur WLAN
  • WPA3 : Wi-Fi Protected Access 3 - sécurité Wi-Fi
  • WWW : World Wide Web - toile mondiale

X

  • X.25 : protocole WAN historique
  • XDP : eXpress Data Path - chemin de données express (eBPF)
  • XML : eXtensible Markup Language - langage de balisage

Y

  • YANG : Yet Another Next Generation - langage de modélisation de données
  • YAML : YAML Ain't Markup Language - format de sérialisation

Z

  • ZBR : Zero Balance Recovery - récupération de solde nul
  • Zero Trust : modèle de sécurité "ne jamais faire confiance"
  • ZTP : Zero Touch Provisioning - provisionnement sans intervention
  • ZTNA : Zero Trust Network Access - accès réseau Zero Trust

Partie 2 : Cheat Sheets

Cheat Sheet 1 : Subnetting

Masques CIDR -> Décimaux :
/24 = 255.255.255.0   = 256 adresses (254 hôtes)
/25 = 255.255.255.128 = 128 (126)
/26 = 255.255.255.192 =  64  (62)
/27 = 255.255.255.224 =  32  (30)
/28 = 255.255.255.240 =  16  (14)
/29 = 255.255.255.248 =   8   (6)
/30 = 255.255.255.252 =   4   (2)
/31 = 255.255.255.254 =   2   (0 - p2p)
/32 = 255.255.255.255 =   1   (0 - host)

Formules :
Nombre de sous-réseaux = 2^(bits empruntés)
Nombre d'hôtes = 2^(32 - CIDR) - 2
Adresse réseau   = IP & Masque
Adresse broadcast = Réseau + Complément masque

Table rapide /24 -> /30 :
/24 -> 1 x 256 hôtes
/25 -> 2 x 128
/26 -> 4 x 64
/27 -> 8 x 32
/28 -> 16 x 16
/29 -> 32 x 8
/30 -> 64 x 4

Plages privées RFC 1918 :
10.0.0.0/8
172.16.0.0/12
192.168.0.0/16

Cheat Sheet 2 : OSPF

Commandes de base :
router ospf 1
  router-id 1.1.1.1
  network 10.0.0.0 0.255.255.255 area 0
  passive-interface default
  no passive-interface GigabitEthernet0/0

Zones :
area 0          = Backbone (transit)
area X          = Normal
area X stub             = Stub (pas de type 5)
area X stub no-summary  = Totally Stubby
area X nssa             = NSSA (type 7)
area X nssa no-summary  = NSSA Totally Stubby

Vérification :
show ip ospf neighbor
show ip ospf interface
show ip ospf database
show ip ospf
show ip route ospf
debug ip ospf adj
debug ip ospf events

Timers :
hello = 10s (broadcast), 30s (NBMA)
dead  = 40s (broadcast), 120s (NBMA)
ip ospf hello-interval 5
ip ospf dead-interval 15

Cost :
ip ospf cost 10
auto-cost reference-bandwidth 10000 (pour 10Gbps +)
Coût par défaut = 10^8 / bandwidth

Redistribution :
redistribute bgp 65000 subnets route-map BGP-TO-OSPF
redistribute static metric 200

Authentification :
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 CLE
area 0 authentication message-digest

Cheat Sheet 3 : BGP

Configuration :
router bgp 65000
  bgp router-id 1.1.1.1
  neighbor 10.0.0.2 remote-as 65001
  neighbor 10.0.0.2 update-source Loopback0
  neighbor 10.0.0.2 ebgp-multihop 2
  neighbor 10.0.0.2 password CLE_BGP
  network 203.0.113.0 mask 255.255.255.0
  maximum-paths 4

Route Reflector :
  neighbor 10.0.0.3 route-reflector-client
  bgp cluster-id 1.1.1.1

Path Selection (ordre Cisco) :
1. Weight (plus haut)
2. LOCAL_PREF (plus haut)
3. Origine (IGP < EGP < ?)
4. AS_PATH (plus court)
5. MED (plus bas)
6. eBGP > iBGP
7. IGP metric to NEXT_HOP

Communities :
ip community-list standard 100 permit 65001:100
route-map SET-COMMUNITY permit 10
  match ip address prefix-list CLIENTS
  set community 65001:100
  set local-preference 200

Vérification :
show ip bgp summary
show ip bgp
show ip bgp 203.0.113.0
show ip bgp community 65001:100
show ip bgp regexp ^65000_
debug ip bgp updates
debug ip bgp keepalives

Prefix-list :
ip prefix-list FILTER seq 5 permit 10.0.0.0/8 le 24
ip prefix-list FILTER seq 10 deny 0.0.0.0/0 le 32

Cheat Sheet 4 : iptables/nftables

iptables syntax :
iptables -t <table> -A <chain> <matches> -j <target>

Tables : filter, nat, mangle, raw, security
Chaines : INPUT, OUTPUT, FORWARD, PREROUTING, POSTROUTING

Commandes courantes :
iptables -L -n -v             # Lister règles
iptables -F                   # Flush
iptables -P INPUT DROP        # Politique DROP
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to 10.0.0.10:80
iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT

nftables :
nft add table inet filter
nft add chain inet filter input { type filter hook input priority 0 \; }
nft add rule inet filter input tcp dport 22 accept
nft add rule inet filter input ct state established,related accept
nft add set inet filter allowed_ports { type inet_service \; }
nft add element inet filter allowed_ports { 80, 443 }

iptables -> nftables translation :
iptables-translate -A INPUT -p tcp --dport 80 -j ACCEPT

Cheat Sheet 5 : Wireshark Display Filters

ip.addr == 10.0.0.1
ip.src == 10.0.0.0/24
ip.dst == 192.168.1.1

tcp.port == 80
tcp.flags.syn == 1
tcp.flags.syn == 1 && tcp.flags.ack == 0
tcp.analysis.retransmission
tcp.analysis.fast_retransmission
tcp.analysis.ack_rtt

udp.port == 53
dns.qry.name == "example.com"
dns.flags.response == 0
dns.flags.rcode == 3  # NXDOMAIN

http.request.method == "GET"
http.request.method == "POST"
http.response.code == 404
http.host == "example.com"

icmp
icmp.type == 8   # Echo request
icmp.type == 0   # Echo reply

arp
arp.opcode == 1   # Request
arp.opcode == 2   # Reply

tls.handshake.type == 1  # Client Hello
tls.handshake.type == 2  # Server Hello

vxlan
bgp
ospf
stp

!(arp or icmp)     # Exclure ARP et ICMP
tcp.port == 80 && ip.src == 10.0.0.0/24

Frame contains "password"
http.request.uri contains "login"

Cheat Sheet 6 : tcpdump

Options :
-i eth0          : interface
-w file.pcap    : écrire dans fichier
-r file.pcap    : lire fichier
-n              : pas de résolution DNS
-nn             : pas de résolution DNS ni de ports
-X              : hex + ASCII
-XX             : avec en-tête Ethernet
-v, -vv, -vvv   : verbosité
-s 0            : capture complète
-c 100          : arrêter après 100 paquets
-p              : pas de promiscuous mode

Expressions :
host 10.0.0.1
src 10.0.0.1
dst 10.0.0.1
net 10.0.0.0/8
port 80
portrange 8000-9000
tcp
udp
icmp
ip6

Exemples :
tcpdump -i eth0 -nn host 10.0.0.1
tcpdump -i eth0 -X port 443
tcpdump -i eth0 -w capture.pcap -s 0
tcpdump -i eth0 'tcp[tcpflags] & (tcp-syn) != 0'
tcpdump -i eth0 'port 80 and (src 10.0.0.0/24 or src 192.168.0.0/16)'
tcpdump -r capture.pcap -X -c 50

Cheat Sheet 7 : Kubernetes Networking

Services :
ClusterIP  : svc accessible dans le cluster
NodePort   : port sur chaque nœud (30000-32767)
LoadBalancer : LB cloud
ExternalName : alias DNS externe

Network Policies :
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
spec:
  podSelector:
    matchLabels:
      app: backend
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: frontend
      ports:
        - port: 80

Ingress :
apiVersion: networking.k8s.io/v1
kind: Ingress
spec:
  rules:
    - host: app.example.com
      http:
        paths:
          - pathType: Prefix
            path: "/"
            backend:
              service:
                name: app-svc
                port:
                  number: 80

Commandes réseau utiles :
kubectl run test --image=nicolaka/netshoot -it --rm -- /bin/bash
kubectl exec pod -- curl http://svc:80
kubectl describe svc <name>
kubectl describe networkpolicy <name>
kubectl get endpoints <name>
kubectl get networkpolicy --all-namespaces

Cheat Sheet 8 : VLAN/VXLAN/EVPN

VLAN 802.1Q :
vlan 10
 name Clients
interface Gi0/1
 switchport mode access
 switchport access vlan 10
interface Gi0/24
 switchport mode trunk
 switchport trunk allowed vlan 10,20,30
 switchport native vlan 99

VXLAN manuel (Linux) :
ip link add vxlan100 type vxlan id 100 \
  local 192.168.10.1 remote 192.168.10.2 \
  dstport 4789 dev eth0

EVPN FRRouting :
router bgp 65000
 address-family l2vpn evpn
  neighbor 10.0.0.2 activate
  advertise-all-vni

EVPN Route Types :
Type 1 : Ethernet Auto-Discovery (ESI)
Type 2 : MAC/IP Advertisement
Type 3 : IMET (Inclusive Multicast)
Type 4 : Ethernet Segment
Type 5 : IP Prefix

Partie 3 : Index des RFCs Essentielles

RFCs Fondamentales

RFCTitreAnnée
1Host Software1969
768UDP1980
791IPv41981
792ICMP1981
793TCP1981
826ARP1982
854Telnet1983
951Bootstrap Protocol (BOOTP)1985
1034DNS - Concepts1987
1035DNS - Implementation1987
1058RIP v11988
1112IGMP1989
1149IP over Avian Carriers1990
1191Path MTU Discovery1990
1256ICMP Router Discovery1991

RFCs Routage (1993-2000)

RFCTitreAnnée
1519CIDR1993
1723RIP v21994
1771BGP-41995
1918Address Allocation for Private Internets1996
2001IPv6 Basic Architecture1996
2131DHCP1997
2328OSPF v21998
2401IPsec Architecture1998
2453RIP v2 (obsolete 1723)1998
2460IPv6 Specification1998
2474DSCP1998
2545BGP-4 Multiprotocol Extensions for IPv61999
2660SST (Secure Socket Tunneling)1999

RFCs Modernes (2000-2010)

RFCTitreAnnée
3031MPLS Architecture2001
3046DHCP Relay Agent Information (Option 82)2001
3065BGP Confederations2001
3101OSPF NSSA2003
3390TCP Slow Start2002
3439Internet Architectural Guidelines2002
3621Power over Ethernet (PoE) MIB2003
3748Extensible Authentication Protocol (EAP)2004
3768VRRP2004
3810MLD v22004
3927Link-Local IPv4 Addresses (169.254.0.0/16)2005
3985Pseudo Wire Emulation Edge-to-Edge (PWE3)2005
4033DNSSEC Introduction2005
4113SNMP MIB2005
4193Unique Local IPv6 Unicast Addresses (FD00::/8)2005
4271BGP-4 (révision)2006
4291IPv6 Addressing Architecture2006
4301IPsec Architecture (révision)2005
4364BGP/MPLS IP VPNs2006
4443ICMPv62006

RFCs Sécurité

RFCTitreAnnée
5246TLS 1.22008
5280PKIX Certificate Profile2008
5343SNMP Context EngineID2008
5452DNS Resilience Against Forged Replies2009
5480Elliptic Curve Cryptography Subject Keys2009
5705Keying Material Exporters for TLS2010
5925TCP Authentication Option (TCP-AO)2010
6066TLS Extensions (SNI)2011
6125Certificate Identity in TLS2011
6818Updates to PKIX2013
6960OCSP2013
6961TLS Multiple Certificate Status2013
7235HTTP Authentication2014
7250TLS Raw Public Keys2014
7301TLS ALPN2014
7366TLS Encrypted Alerts2014
7540HTTP/22015
7918TCP Encryption (TCP-ENO)2016
7924TLS Cached Info Extension2016
8446TLS 1.32018

RFCs Cloud et Virtualisation

RFCTitreAnnée
4555IKEv2 Mobility and Multihoming (MOBIKE)2006
4861Neighbor Discovery for IPv62007
4862IPv6 Stateless Address Autoconfiguration2007
4941Privacy Extensions for IPv62007
5214LISP (Locator/ID Separation Protocol)2008
5517Cisco's VSS Architecture2009
5720Routing Information Protocol (RIP) Cryptographic Authentication2010
5905NTP v42010
5965BGP Large Communities2012
6071IPsec/IKEv2 Roadmap2011
6437IPv6 Flow Label2011
6452Extended Unique Identifier (EUI-64)2011
6727YANG Module for OSPF2012
6830LISP (révision)2013
7348VXLAN2014
7432BGP MPLS-Based EVPN2015
7911BGP ADD-PATH2016
7938Clos Datacenter Networks2016
8200IPv6 (révision)2017
8365EVPN VXLAN2018
8402Segment Routing Architecture2018
8660SR-MPLS2019
8986SRv62021
9000QUIC2021
9113HTTP/2 (révision)2022
9114HTTP/32022
9135Anycast Gateway EVPN2022
9252SRv6 with EVPN2022

Partie 4 : Ports Well-Known

Ports 1-100 (Essentiels)

PortTCP/UDPProtocoleDescription
7TCP/UDPEchoEcho service
9TCP/UDPDiscardDiscard service
13TCP/UDPDaytimeDate/heure
17TCP/UDPQOTDQuote of the Day
19TCP/UDPChargenCharacter Generator
20TCPFTP-DataFTP données
21TCPFTPFTP contrôle
22TCPSSHSecure Shell
23TCPTelnetTelnet (non sécurisé)
25TCPSMTPEmail sortant
37TCP/UDPTimeTime protocol
42TCP/UDPNameserverWINS
43TCPWHOISWHOIS
49TCP/UDPTACACSTACACS
53TCP/UDPDNSDomain Name System
67UDPDHCP-ServerDHCP serveur
68UDPDHCP-ClientDHCP client
69UDPTFTPTrivial FTP
70TCPGopherGopher
79TCPFingerFinger
80TCPHTTPWeb
88TCPKerberosKerberos
109TCPPOP2POP version 2
110TCPPOP3POP version 3
111TCP/UDPRPCSun RPC / Portmapper
113TCPIdentIdentification
119TCPNNTPUsenet
123UDPNTPNetwork Time Protocol
135TCP/UDPRPCMicrosoft RPC / EPMAP
137TCP/UDPNetBIOS-NSNetBIOS Name Service
138UDPNetBIOS-DGMNetBIOS Datagram
139TCPNetBIOS-SSNNetBIOS Session
143TCPIMAPIMAP v2/v4
161UDPSNMPSNMP Agent
162UDPSNMP-TrapSNMP Traps
179TCPBGPBorder Gateway Protocol
194TCP/UDPIRCInternet Relay Chat
199TCP/UDPSMUXSNMP SMUX
201TCP/UDPAppleTalkAppleTalk
389TCPLDAPLDAP
443TCPHTTPSHTTP over TLS
445TCPSMBSMB/CIFS
464TCP/UDPkpasswdKerberos password
465TCPSMTPSSMTP over SSL
500UDPIKEIKE (IPsec)
502TCP/UDPModbusModbus protocol
512TCPrexecRemote exec
513TCPrloginRemote login
513UDPrwhoRemote who
514TCPrshRemote shell
514UDPsyslogSyslog
515TCPLPDLine Printer Daemon
520UDPRIPRouting Information Protocol
521UDPRIPngRIP next generation
524TCP/UDPNCPNetWare Core Protocol
540TCPUUCPUUCP
543TCPkloginKerberos login
544TCPkshellKerberos shell
546TCP/UDPDHCPv6DHCPv6 Client
547TCP/UDPDHCPv6DHCPv6 Server
548TCPAFPApple Filing Protocol
550UDPnew-rwhoNew rwho
554TCPRTSPReal Time Streaming Protocol
560UDPrmonitorRemote monitor
561UDPmonitorMonitor
563TCP/UDPNNTPNNTP over TLS
585TCPIMAP4IMAP4 over TLS
587TCPSMTPSMTP Submission
591TCPFileMakerFileMaker
593TCP/UDPRPCHTTP RPC
623UDPIPMIIPMI RMCP
625TCPNCPNCP over TLS
626TCPAppleShareAppleShare
631TCP/UDPIPPInternet Printing Protocol
636TCPLDAPSLDAP over TLS
639TCP/UDPMSDPMulticast Source Discovery
646TCP/UDPLDPLabel Distribution Protocol (MPLS)
647TCPDHCP-FailoverDHCP Failover
648TCPRRPRegistry Registrar
651TCP/UDPIEEE-MMSIEEE Media Management
653TCPIEHTTPIE HTTP
654TCPMPEGMPEG
655TCPTINCTINC VPN
657TCP/UDPRMCRemote Media Control
660TCPMACMac OS X
661TCP/UDPIPXIPX
662TCPIPXIPX File Service
666TCP/UDPDoomDoom Id
674TCPACAPACAP
688TCP/UDPREALM-RUSDREALM
690TCPVATPVATP
691TCPMS-RPCMS Exchange
694TCP/UDPHA-CLUSTERHeartbeat
695TCPIEEE-MMSIEEE Media Management
698UDPOLSROLSR
699TCP/UDPAccessAccess Network
700TCPEPPExtensible Provisioning (EPP)
701TCPLMPLink Management (LMP)
702TCPIRISIRIS over BEEP
706TCPSILCSILC
711TCPTDPTag Distribution (MPLS)
712TCP/UDPTBRPFTBRPF
749TCPKerberosKerberos admin
750UDPKerberosKerberos v4
751TCP/UDPKerberosKerberos v4
752UDPKerberosKerberos v4 passwd
753TCPKerberosKerberos v4
754TCPKerberosKerberos v4
760TCP/UDPkrbupdateKerberos update
763TCP/UDPpmdPMD
767TCP/UDPphonePhone
768TCP/UDPpadl2PADL2
771TCP/UDPrtipRTIP
772TCP/UDPcycleservCycleserv
773TCP/UDPsubmitSubmit
774TCP/UDPrpasswdRemote password
775TCP/UDPentombEntomb
776TCP/UDPwpagesWpages
777TCP/UDPmultilingMultiling HTTP
780TCP/UDPwpgsWpgs
800TCP/UDPmdbs_daemonMDBS
801TCP/UDPdeviceDevice
810TCP/UDPfcpFCP
828TCP/UDPitmITM

Ports Importants 1000-50000

PortTCP/UDPProtocole
1080TCPSOCKS Proxy
1194UDPOpenVPN
1433TCPSQL Server (MSSQL)
1434UDPSQL Server Monitor
1521TCPOracle Database
1701UDPL2TP
1723TCPPPTP
1812UDPRADIUS Authentication
1813UDPRADIUS Accounting
1883TCPMQTT
2375TCPDocker API (non-TLS)
2376TCPDocker API (TLS)
2379TCPetcd client
2380TCPetcd peer
2483TCPOracle DB
2484TCPOracle DB (TLS)
2948TCP/UDPWAP (WAP Push)
2949TCP/UDPWAP (WAP Push)
3000TCPGrafana / PrestaShop / Node.js dev
3128TCPSquid HTTP Proxy
3306TCPMySQL / MariaDB
3389TCPRDP (Remote Desktop)
3689TCPDAAP (Apple iTunes)
3690TCPSubversion (SVN)
3724TCPWorld of Warcraft
3784UDPBFD (Bidirectional Forwarding Detection)
3785UDPBFD
4000TCPICQ / Diablo 3
4045UDPNFS lockd
4190TCPManageSieve
4333TCPmSQL (Mini SQL)
4343TCPUNICALL
4444TCPMetaHTTP / Blizzard
4500UDPIPsec NAT-Traversal
4567TCPSinatra (development)
4662TCPeMule
4672UDPeMule
4711TCPPulseAudio
4713TCPPulseAudio
4840TCP/UDPOPC UA MPC
4843TCP/UDPOPC UA MPC (TLS)
4848TCPGlassFish Admin
4899TCPRadmin
5000TCPFlask / Docker Registry / UPnP
5001TCPiPerf / Synology DSM
5004UDPRTP (media)
5005UDPRTP (control)
5038TCPAsterisk Manager
5039TCPAsterisk HTTP
5040TCPAsterisk HTTP
5050TCPYahoo! Messenger
5060TCP/UDPSIP
5061TCPSIP-TLS
5070UDPSIP
5222TCPXMPP Client
5223TCPXMPP Client (TLS)
5269TCPXMPP Server
5349TCP/UDPSTUN/TURN (TLS)
5351UDPNAT-PMP (Apple)
5353UDPmDNS (Bonjour)
5355UDPLLMNR
5432TCPPostgreSQL
5445UDPCisco Unified Presence
5450TCPOSIsoft PI
5500TCPVNC Listener
5510TCPVNC
5520TCPVNC
5530TCPVNC
5540TCPVNC
5550TCPVNC
5554TCPVNC
5555TCPAndroid ADB
5560TCPVNC
5570TCPVNC
5580TCPVNC
5590TCPVNC
5591TCPVNC
5592TCPVNC
5593TCPVNC
5594TCPVNC
5595TCPVNC
5596TCPVNC
5597TCPVNC
5598TCPVNC
5599TCPVNC
5600TCPVNC
5631TCPpcAnywhere
5632UDPpcAnywhere
5666TCPNRPE (Nagios)
5671TCPAMQP (TLS)
5672TCPAMQP (RabbitMQ)
5683UDPCoAP
5850TCPOpenVG
5900TCPVNC (RFB)
5938TCPTeamViewer
5984TCPCouchDB
5985TCPWinRM (HTTP)
5986TCPWinRM (HTTPS)
6000-6009TCPX11
6346TCP/UDPGnutella
6347TCP/UDPGnutella
6379TCPRedis
6443TCPKubernetes API (HTTPS)
6480TCPCIFS
6514TCPSyslog (TLS)
6566TCPSANE
6600TCPMPD (Music Player Daemon)
6660-6669TCPIRC (commonly)
6679TCPIRC SSL
6697TCPIRC SSL
6701TCPKTI/ICAD
6789TCPCampfire
6881-6889TCP/UDPBitTorrent
6891-6900TCP/UDPBitTorrent
6901TCP/UDPBitTorrent
6969TCPBitTorrent Tracker
6970UDPReal Audio
6998TCPIAX2
7000TCPDefault (many apps)
7001TCPWebLogic / BEA
7002TCPWebLogic (SSL)
7004TCPWebLogic
7005TCPWebLogic
7007TCPWebLogic
7070TCPReal Server
7071TCPZimbra Admin
7100TCPX Font Server
7171TCPTibco
7200TCPVeritas Cluster
7201TCPVeritas Cluster
7283TCPGNS3
7301TCPDNS
7312UDPDNS
7391TCPHP OpenView
7420TCPUPS
7421TCPUPS
7443TCPOracle HTTPS / OVF
7447TCPVMware Server
7474TCPNeo4j Browser
7475TCPNeo4j
7496UDPiPerf3
7547TCPCWMP (TR-069)
7548TCPCWMP
7575TCPPMP
7624TCPPMP
7675UDPRTP
7676TCPRTP
7717TCPKaseya
7741TCPVAVS
7777TCPiChat / Oracle
7778TCPiChat / Oracle
8000TCPHTTP Alternate (many apps)
8005TCPTomcat Shutdown
8008TCPHTTP Alternate
8009TCPAJP (Tomcat)
8010TCPXMPP File Transfer
8020TCPApache JServ
8042TCPOAA
8060TCPP2P
8070TCPTIBCO
8080TCPHTTP Proxy (Tomcat, etc.)
8081TCPHTTP Proxy (Alternate)
8082TCPHTTP Proxy
8083TCPHTTP Proxy
8084TCPHTTP Proxy (e.g. Varnish)
8085TCPHTTP Proxy
8086TCPInfluxDB HTTP
8087TCPInfluxDB RPC
8088TCPInfluxDB Backup
8089TCPSplunk
8090TCPHTTP Alternate
8096TCPEmby
8100TCPMSMQ
8111TCPDefault (proxy)
8112TCPPAC Pacific
8118TCPPrivoxy
8123TCPPolipo (proxy)
8139TCPPuppet
8140TCPPuppet CA
8172TCPMS Deployment Services
8200TCPGoToMyPC
8222TCPVMware Server
8243TCPHTTPS Alternate
8280TCPHTTP Alternate
8291TCPMikroTik RouterOS Winbox
8300TCPTIBCO
8332TCPBitcoin JSON-RPC
8333TCPBitcoin
8334TCPBitcoin
8384TCPSyncthing (GUI)
8400TCPCommVault
8401TCPCommVault
8402TCPCommVault
8403TCPCommVault
8404TCPCommVault
8405TCPCommVault
8443TCPHTTPS Alternate (Tomcat, etc.)
8500TCPConsul (HTTP API)
8501TCPConsul (HTTPS)
8530TCPWS-Management
8531TCPWS-Management (TLS)
8590TCPContinua
8600TCPStoneGate
8612TCPCanon BJNP
8649TCPGanglia
8651UDPGanglia
8652UDPGanglia
8666TCPMUM
8686TCPSun RMI
8765TCPApache (many)
8778TCPTCP
8786TCPTCP
8787TCPMSMQ
8800TCPSun Web Server
8880TCPHTTP (Alternate)
8881TCPHTTP (Alternate)
8882TCPHTTP (Alternate)
8883TCPMQTT (TLS)
8888TCPHTTP (Alternate/Proxy)
8889TCPHTTP (Alternate)
8890TCPHTTP
8891TCPHTTP
8892TCPHTTP
8893TCPHTTP
8894TCPHTTP
8895TCPHTTP
8896TCPHTTP
8897TCPHTTP
8898TCPHTTP
8899TCPHTTP
9000TCPPHP-FPM / SonarQube
9001TCPTor / Supervisord
9002TCPDefault
9003TCPDefault
9004TCPDefault
9005TCPDefault
9006TCPDefault
9007TCPDefault
9008TCPDefault
9009TCPPichat
9010TCPSDR
9042TCPCassandra (CQL)
9043TCPWebSphere Admin
9050TCPTor SOCKS
9060TCPWebSphere
9080TCPWebSphere HTTP
9090TCPPrometheus / Cisco ACS
9092TCPKafka
9093TCPPrometheus Alertmanager
9094TCPPrometheus (cluster)
9100TCPJetDirect / Node Exporter
9117TCPSyncthing
9150TCPTor Control
9160TCPCassandra (Thrift)
9191TCPSierra Wireless
9200TCPElasticsearch
9210TCPElasticsearch
9292TCPOpenStack Glance
9300TCPElasticsearch (cluster)
9312TCPSphinx Search
9324TCPElasticsearch
9332TCPLitecoin JSON-RPC
9333TCPLitecoin
9418TCPGit (Smart HTTP)
9443TCPVMware vCenter
9535TCPMNG
9600TCPMicromuse
9753UDPApple
9876TCPSDL
9898TCPTripwire
9900TCPIUA
9901UDPIUA (SCTP)
9981TCPPlex Media (HTTP)
9982TCPPlex (HTTPS)
9999TCPDefault (many)
10000TCPWebmin / BackupPC
10001TCPLantronix
10009TCPCrossbeam
10010TCPOpenAPI
10050TCPZabbix Agent
10051TCPZabbix Server
10113TCPNetIQ
10114TCPNetIQ
10115TCPNetIQ
10116TCPNetIQ
10117TCPNetIQ
10125TCPCimple
10128TCPBMC
10129TCPBMC
10200TCPFRISK
10201TCPFRISK
10288TCPApple
10301TCPBackup Exec
10302TCPBackup Exec
10303TCPBackup Exec
10304TCPBackup Exec
10305TCPBackup Exec
10306TCPBackup Exec
10307TCPBackup Exec
10308TCPBackup Exec
10309TCPBackup Exec
10310TCPBackup Exec
10443TCPCitrix
10554UDPCitrix
10666TCPAMA
11000TCPIRC / SACS
11111TCPRiCcI
11211TCP/UDPMemcached
11371TCP/UDPOpenPGP HTTP Keyserver
11400TCPSoundBridge
11489TCPASG
11600TCPTempest
11720TCPBackup
11721TCPBackup
11722TCPBackup
11723TCPBackup
11724TCPBackup
11725TCPBackup
11726TCPBackup
11727TCPBackup
11728TCPBackup
11729TCPBackup
11730TCPBackup
11999TCPTFO
12000TCPEntran
12001TCPEntran
12002TCPEntran
12003TCPEntran
12004TCPEntran
12005TCPEntran
12006TCPEntran
12007TCPEntran
12008TCPEntran
12009TCPEntran
12010TCPEntran
12011TCPEntran
12012TCPEntran
12013TCPEntran
12345TCPNetBus
12350TCPHuawei
13720TCP/UDPSymantec NetBackup
13721TCP/UDPSymantec NetBackup
13722TCP/UDPSymantec NetBackup
13724TCP/UDPSymantec Network
13782UDPSymantec NetBackup
13783UDPSymantec NetBackup
13785UDPNetBackup
13786UDPNetBackup
13818UDPDSMCC
13819UDPDSMCC
13820UDPDSMCC
13821UDPDSMCC
13822UDPDSMCC
13823UDPDSMCC
13824UDPDSMCC
13894TCP/UDPQuickTime
13900TCPMediaCentral
13929TCPD-Trace
14000TCPSCOTTY
14001TCPSCOTTY
14002TCPSCOTTY
14033TCPSage
14034TCPSage
14141TCPVCS
14142TCPVCS
14143TCPVCS
14144TCPVCS
14145TCPVCS
14146TCPVCS
14147TCPVCS
14148TCPVCS
14149TCPVCS
14150TCPVCS
14151TCPVCS
14152TCPVCS
14153TCPVCS
14154TCPVCS
14441TCPVCS
14442TCPVCS
15000TCPSAP
15002TCPSAP
15003TCPSAP
15004TCPSAP
15005TCPSAP
15006TCPSAP
15118UDPUDP
15345TCPXPilot
16001TCPMSSQL
16010TCP
16020TCP
16030TCP
16161TCPSun
16309TCP
16310TCP
16311TCP
16384UDPCISCO
16385UDPCISCO
16386UDPCISCO
16387UDPCISCO
16388UDPCISCO
16389UDPCISCO
16390UDPCISCO
16391UDPCISCO
16392UDPCISCO
16393UDPCISCO
16394UDPCISCO
16395UDPCISCO
16396UDPCISCO
16397UDPCISCO
16398UDPCISCO
16399UDPCISCO
16400UDPCISCO
16401UDPCISCO
16402UDPCISCO
16403UDPCISCO
16404UDPCISCO
16405UDPCISCO
16406UDPCISCO
16407UDPCISCO
16408UDPCISCO
16409UDPCISCO
16410UDPCISCO
16411UDPCISCO
16412UDPCISCO
16413UDPCISCO
16414UDPCISCO
16415UDPCISCO
16416UDPCISCO
16417UDPCISCO
16418UDPCISCO
16419UDPCISCO
16420UDPCISCO
16421UDPCISCO
16422UDPCISCO
16423UDPCISCO
16424UDPCISCO
16425UDPCISCO
16426UDPCISCO
16427UDPCISCO
16428UDPCISCO
16429UDPCISCO
16430UDPCISCO
16431UDPCISCO
16432UDPCISCO
16433UDPCISCO
16434UDPCISCO
16435UDPCISCO
16436UDPCISCO
16437UDPCISCO
16438UDPCISCO
16439UDPCISCO
16440UDPCISCO
16441UDPCISCO
16442UDPCISCO
16443UDPCISCO
16444UDPCISCO
16445UDPCISCO
16446UDPCISCO
16447UDPCISCO
16448UDPCISCO
16449UDPCISCO
16450UDPCISCO
16451UDPCISCO
16452UDPCISCO
16453UDPCISCO
16454UDPCISCO
16455UDPCISCO
16456UDPCISCO
16457UDPCISCO
16458UDPCISCO
16459UDPCISCO
16460UDPCISCO
16461UDPCISCO
16462UDPCISCO
16463UDPCISCO
16464UDPCISCO
16465UDPCISCO
16466UDPCISCO
16467UDPCISCO
16468UDPCISCO
16469UDPCISCO
16470UDPCISCO
16471UDPCISCO
16472UDPCISCO
16473UDPCISCO
16474UDPCISCO
16475UDPCISCO
16476UDPCISCO
16477UDPCISCO
16478UDPCISCO
16479UDPCISCO
16480UDPCISCO
16481UDPCISCO
16482UDPCISCO
16483UDPCISCO
16484UDPCISCO
16485UDPCISCO
16486UDPCISCO
16487UDPCISCO
16488UDPCISCO
16489UDPCISCO
16490UDPCISCO
16491UDPCISCO
16492UDPCISCO
16493UDPCISCO
16494UDPCISCO
16495UDPCISCO
16496UDPCISCO
16497UDPCISCO
16498UDPCISCO
16499UDPCISCO
16500UDPCISCO
16501UDPCISCO
16502UDPCISCO
16503UDPCISCO
16504UDPCISCO
16505UDPCISCO
16506UDPCISCO
16507UDPCISCO
16508UDPCISCO
16509UDPCISCO
16510UDPCISCO
16511UDPCISCO
16512UDPCISCO
16513UDPCISCO
16514UDPCISCO
16515UDPCISCO
16516UDPCISCO
16517UDPCISCO
16518UDPCISCO
16519UDPCISCO
16520UDPCISCO
16521UDPCISCO
16522UDPCISCO
16523UDPCISCO
16524UDPCISCO
16525UDPCISCO
16526UDPCISCO
16527UDPCISCO
16528UDPCISCO
16529UDPCISCO
16530UDPCISCO
16531UDPCISCO
16532UDPCISCO
16533UDPCISCO
16534UDPCISCO
18080TCP
18200TCP
18181TCP
18201TCP
18202TCP
18203TCP
18300TCP
18301TCP
18302TCP
18303TCP
18304TCP
18305TCP
18306TCP
18988TCP
19101TCP
19283TCP
19315TCP
19350TCP
19540TCP
20000TCPDNP (Distributed Network Protocol)
20560TCP
20670TCP
20999TCP
21000TCP
21010TCP
21212TCP
21213TCP
21544TCP
21554TCP
21590TCP
21800TCP
21801TCP
21802TCP
21803TCP
21804TCP
21805TCP
21806TCP
21807TCP
21808TCP
21809TCP
22222TCPDefault
22273TCP
22305TCP
22335TCP
22951TCP
23000TCP
23001TCP
23002TCP
23003TCP
23004TCP
23005TCP
23006TCP
23007TCP
23008TCP
23009TCP
23010TCP
23011TCP
23012TCP
23013TCP
23014TCP
23015TCP
23016TCP
23017TCP
23018TCP
23019TCP
23020TCP
23021TCP
23022TCP
23023TCP
23024TCP
23025TCP
23026TCP
23027TCP
23028TCP
23029TCP
23030TCP
23031TCP
23032TCP
23033TCP
23034TCP
23035TCP
23036TCP
23037TCP
23038TCP
23039TCP
23040TCP
23041TCP
23042TCP
23043TCP
23044TCP
23045TCP
23046TCP
23047TCP
23048TCP
23049TCP
23050TCP
23272UDP
23399TCP
23513TCP
24000TCP
24386TCP
24465TCP
24554TCP
24577TCP
24676TCP
24677TCP
25678TCP
25734TCP
25735TCP
26000TCP
26133TCP
26208TCP
26260TCP
26261TCP
26262TCP
26263TCP
26264TCP
26265TCP
26266TCP
26267TCP
26268TCP
26269TCP
26270TCP
26271TCP
26272TCP
26273TCP
26274TCP
26275TCP
26276TCP
26277TCP
26278TCP
26279TCP
26280TCP
26281TCP
26282TCP
26283TCP
26284TCP
26285TCP
26286TCP
26287TCP
26288TCP
26289TCP
26290TCP
26291TCP
26292TCP
26293TCP
26294TCP
26295TCP
26296TCP
26297TCP
26298TCP
26299TCP
26300TCP
27000TCPFlexLM / PowerBuilder
27374TCPSubSeven
27015UDPSteam / Source
27016UDPSteam
27444UDP
27500UDP
27666TCP
27800TCP
27900UDP
27901UDP
27910UDP
27960UDP
27961UDP
27992UDP
28000TCP
28001TCP
28002TCP
28003TCP
28004TCP
28005TCP
28006TCP
28007TCP
28008TCP
28009TCP
28010TCP
28138TCP
28369TCP
28442TCP
28443TCP
28444TCP
28445TCP
28446TCP
28447TCP
28448TCP
28449TCP
28652TCP
28910TCP
28960TCP/UDPCall of Duty
29000TCP
29001TCP
29002TCP
29003TCP
29004TCP
29005TCP
29006TCP
29007TCP
29008TCP
29009TCP
29010TCP
29011TCP
29012TCP
29013TCP
29014TCP
29015TCP
29900TCP
29901TCP
29920TCP
30000TCP
30001TCP
30002TCP
30003TCP
30004TCP
30005TCP
30006TCP
30007TCP
30008TCP
30009TCP
30010TCP
30011TCP
30012TCP
30013TCP
30014TCP
30015TCP
30016TCP
30017TCP
30018TCP
30019TCP
30020TCP
30100TCP
30260UDP
30400TCP
30701TCP
30704TCP
30705TCP
30706TCP
30707TCP
30708TCP
30709TCP
30710TCP
30718TCP
30720TCP
30721TCP
30722TCP
30723TCP
30724TCP
30725TCP
30726TCP
30727TCP
30728TCP
30729TCP
30730TCP
30731TCP
30732TCP
30733TCP
30734TCP
30735TCP
30736TCP
30737TCP
30738TCP
30739TCP
30740TCP
30741TCP
30742TCP
30743TCP
30744TCP
30745TCP
30746TCP
30747TCP
30748TCP
30749TCP
30750TCP
30751TCP
30752TCP
30753TCP
30754TCP
30755TCP
30756TCP
30757TCP
30758TCP
30759TCP
30760TCP
30761TCP
30762TCP
30763TCP
30764TCP
30765TCP
30766TCP
30767TCP
30768TCP
30769TCP
30770TCP
30771TCP
30772TCP
30773TCP
30774TCP
30775TCP
30776TCP
30777TCP
30778TCP
30779TCP
30780TCP
30781TCP
30782TCP
30783TCP
30784TCP
30785TCP
30786TCP
30787TCP
30788TCP
30789TCP
30790TCP
30791TCP
30792TCP
30793TCP
30794TCP
30795TCP
30796TCP
30797TCP
30798TCP
30799TCP
30800TCP
31337TCPBack Orifice
31338TCP
31339TCP
31340TCP
31400TCP
31401TCP
31402TCP
31403TCP
31404TCP
31405TCP
31406TCP
31407TCP
31408TCP
31409TCP
31410TCP
31411TCP
31412TCP
31413TCP
31414TCP
31415TCP
31416TCP
31417TCP
31418TCP
31419TCP
31420TCP
31421TCP
31422TCP
31423TCP
31424TCP
31425TCP
31426TCP
31427TCP
31428TCP
31429TCP
31430TCP
31431TCP
31432TCP
31433TCP
31434TCP
31435TCP
31436TCP
31437TCP
31438TCP
31439TCP
31440TCP
31620TCP
31685TCP
31765TCP
31785TCP
31786TCP
31787TCP
31788TCP
31789TCP
31790TCP
31791TCP
31792TCP
31793TCP
31794TCP
31795TCP
31796TCP
31797TCP
31798TCP
31799TCP
31800TCP
31948UDP
32000TCP
32137TCP
32369TCP
32400TCPPlex Media Server
32764TCP
32768TCP/UDPDynamic (first)
32769TCP/UDPDynamic
32770TCP/UDPDynamic
32771TCP/UDPDynamic
32772TCP/UDPDynamic
32773TCP/UDPDynamic
32774TCP/UDPDynamic
32775TCP/UDPDynamic
32776TCP/UDPDynamic
32777TCP/UDPDynamic
32778TCP/UDPDynamic
32779TCP/UDPDynamic
32780TCP/UDPDynamic
32800TCP
32801TCP
32803TCP
32806TCP
32810TCP
32811TCP
32812TCP
32813TCP
32814TCP
32815TCP
32816TCP
32817TCP
32818TCP
32819TCP
32820TCP
32821TCP
32822TCP
33033TCP
33331TCP
33333TCP
33434UDPtraceroute
33656TCP
34249TCP
34324TCP
34444TCP
34445TCP
34555TCP
34601TCP
34855TCP
35000TCP
35354TCP
35355TCP
35356TCP
35357TCP
36000TCP
36103TCP
36104TCP
36105TCP
36106TCP
36107TCP
36108TCP
36109TCP
36110TCP
36111TCP
36112TCP
36113TCP
36114TCP
36115TCP
36116TCP
36117TCP
36118TCP
36119TCP
36120TCP
36206TCP
36207TCP
36208TCP
36209TCP
36210TCP
36211TCP
36212TCP
36213TCP
36214TCP
36215TCP
36216TCP
36217TCP
36218TCP
36219TCP
36220TCP
36221TCP
36222TCP
36223TCP
36224TCP
36225TCP
36226TCP
36227TCP
36228TCP
36229TCP
36230TCP
36231TCP
36232TCP
36233TCP
36234TCP
36235TCP
36236TCP
36237TCP
36238TCP
36239TCP
36240TCP
36241TCP
36242TCP
36243TCP
36244TCP
36245TCP
36246TCP
36247TCP
36248TCP
36249TCP
36250TCP
36251TCP
36252TCP
36253TCP
36254TCP
36255TCP
36256TCP
36257TCP
36258TCP
36259TCP
36260TCP
36261TCP
36262TCP
36263TCP
36264TCP
36265TCP
36266TCP
36267TCP
36268TCP
36269TCP
36270TCP
36271TCP
36272TCP
36273TCP
36274TCP
36275TCP
36276TCP
36277TCP
36278TCP
36279TCP
36280TCP
36281TCP
36282TCP
36283TCP
36284TCP
36285TCP
36286TCP
36287TCP
36288TCP
36289TCP
36290TCP
36291TCP
36292TCP
36293TCP
36294TCP
36295TCP
36296TCP
36297TCP
36298TCP
36299TCP
36300TCP
37008TCP
37601TCP
37602TCP
37603TCP
37604TCP
37605TCP
37606TCP
37607TCP
37608TCP
37609TCP
37610TCP
38000TCP
38001TCP
38002TCP
38201TCP
38202TCP
38203TCP
38800TCP
38865TCP
39683TCP
40000TCPSafetyNET
40841TCP
40842TCP
40843TCP
41111TCP
41121TCP
41122TCP
41123TCP
41124TCP
41125TCP
41126TCP
41127TCP
41128TCP
41129TCP
41333UDP
41794TCP
41795TCP
41796TCP
41797TCP
41798TCP
41799TCP
42508TCP
42509TCP
42510TCP
43000TCP
43118TCP
43119TCP
43120TCP
43594TCP
43595TCP
44334TCP
44123TCP
44321TCP
44322TCP
44334TCP
44442TCP
44443TCP
44444TCP
44445TCP
45000TCP
45001TCP
45002TCP
45045TCP
45054UDP
45514TCP
45555TCP
45556TCP
45678TCP
45824TCP
45825TCP
45966TCP
46336TCP
46998TCP
46999TCP
47000TCP
47001TCP
47557TCP
47624TCP
47806TCP
47808UDPBACnet
47809UDPBACnet
48000TCP
48001TCP
48002TCP
48003TCP
48004TCP
48005TCP
48006TCP
48007TCP
48008TCP
48009TCP
48010TCP
48189UDP
48656TCP
48657TCP
48658TCP
48659TCP
48660TCP
48661TCP
48662TCP
48663TCP
48664TCP
48665TCP
48666TCP
48667TCP
48668TCP
48669TCP
48670TCP
48671TCP
48672TCP
48673TCP
48674TCP
48675TCP
48676TCP
48677TCP
48678TCP
48679TCP
48680TCP
49151TCP/UDPRegistered ports (last)
49152TCP/UDPDynamic/Private (first)
65535TCP/UDPDynamic/Private (last)