Your IP address:
Provider:
...

Open, closed and filtered ports: interpreting a test

A port check reports how one connection attempt appeared from one network location. “Open”, “closed” and “filtered” are useful diagnostic labels, but a single result cannot identify every device involved or determine whether an application is secure.

What the three labels mean

For TCP, open usually means the remote endpoint accepted an attempt to establish a connection. Closed normally means an explicit refusal: the address responded, but no service accepted TCP connections on that port. Filtered, or no response, means the tester could not get a decisive reply before its timeout. A firewall, router or network on the path may have dropped the probe or its answer. The label alone does not reveal which device did it.

Tools may use different probes and wording. UDP is especially difficult to classify by silence because UDP has no built-in connection acknowledgement. A quiet UDP service may exist, and a successful TCP check says nothing about UDP on the same number. Confirm the transport that the application actually uses before changing rules.

Trace the path to a home service

If you host an application at home, first check that it is listening on the intended port and interface. A process bound only to 127.0.0.1 accepts local connections but not requests arriving from the network. Next inspect the host firewall and the router’s forwarding rule. If the provider uses carrier-grade NAT, its shared public IPv4 address may not allow arbitrary incoming connections to your router. Changing a forwarding rule on your own device is then insufficient.

Run the 2ip port check from outside the home network. Testing only from inside can be misleading because NAT loopback behaves differently from real inbound traffic. Compare the external result with the application’s local logs. If the request arrives and the application returns an error, the problem may be at the application layer rather than the port.

Fix the fault without widening access

Do not disable the entire firewall to get a green result. Allow the exact protocol and port needed, restrict permitted source addresses when possible, and keep the exposed service updated. An open port is not automatically a vulnerability, but it allows connection attempts. A closed result does not establish that the whole device is secure: other services may still be reachable.

The network port guide explains port numbers, while the firewall guide covers filtering rules. Scanner state names are useful shorthand only when read alongside the probe type and response.

The IANA service registry lists assigned numbers and transports. An assignment does not prove that traffic on that port is safe or even belongs to the named application.