We’ve Updated Our Terms. We’ve updated our Terms Of ServicePrivacy Policy, and Data Processing Addendum, effective August 6, 2026. Please review the changes before continuing to use our services.

Endpoint-Based Port Filtering Tool to Block TCP/UDP Ports

BrowseControl is a host-based web filtering and port blocking software for restricting internet access and filtering TCP/UDP ports on endpoint devices.

Effortlessly block ports that are unused and exploitable to reduce the attack surface of your network.

$6 USD user/month!

 

4.8/5 avg.

Trusted by 100,000+ professionals in 55 countries.

*No credit card required · 14-day free trial · Easy setup

Capterra-Ease-of-use-2026 Getapp-Best-Functionality-and-features-2025 currentware-g2-fall-2024-high-performer-award-1 300×350-Ready-black (1)
PortFilter-e1614785334244

Over 700 leading government agencies, healthcare organizations, and professional services firms already use CurrentWare.

  • cushing
  • Mendota
  • nebf
  • idaho
  • viking
  • VES
  • Bristol-logo (1)
internet-screen-security-protection-60504-scaled-1

Port Filter to Block Unused Ports

internet-screen-security-protection-60504-scaled-1

BrowseControl’s port filtering feature allows you to block port numbers based on a variety of well-known ports, specific port numbers, or a port range.

 

  • Deny by Default: All ports should be closed by default unless there is a documented, reviewed, and approved business case.
  • Defense in Depth: Combine BrowseControl’s host-based port filtering with a perimeter-based firewall for a defense-in-depth approach.
  • Risk Assessment: Any port can be exploited by an attacker. Blocking unused ports reduces the attack surface of your network.
Firewall-vs-Web-Filter-2

Why Block Ports?

Firewall-vs-Web-Filter-2

Malicious hackers can use port scanning tools to discover open ports in your network.

 

Once they find an available port number they can use it to search for potential vulnerabilities that they can use to gain unauthorized access into your network.

 

By proactively blocking unused ports with port blocking software you can reduce the attack surface available to threat actors and improve network security by making the filtered port inaccessible.

woman-standing-while-carrying-laptop-1181354-1

What is Port Filtering?

woman-standing-while-carrying-laptop-1181354-1

Port filtering is the practice of filtering packets based on port number to restrict traffic within a network.

 

The internet and applications use Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) ports to transmit network protocol packets (data).

 

In a TCP/IP network, a port is a number that identifies the type of network traffic. If an incoming or outgoing port is “closed,” packets with that port number are not allowed into or out of the LAN. With BrowseControl’s port filter these packets are restricted on a per-endpoint basis.

 

Ports 1024 to 49151 are Registered Ports. Ports 49152 to 65535 are Public Ports.

 

Using a port filter allows administrators to restrict specific operations such as file transfers through FTP and torrents. With the filtered port inaccessible you can reduce the attack surface of your network.

cyber-security-3194286_960_720 (2)

Recommended Ports to Block

cyber-security-3194286_960_720 (2)

While any port number can be potentially exploited, there are some ports that are known security risks.

For example, port 20 and 21 are used by the File Transfer Protocol (FTP). Generally, port 21 is used to establish the connection between the 2 computers (or hosts) and port 20 is used to transfer data (via the Data channel).

 

If a Deny-by-Default approach isn’t feasible for your organization, try these recommended ports to block in your port filter.

 

  • Internet Relay Chat (IRC): Botnets can use IRC to communicate with infected machines. Close the port range 6660 – 6669 to block IRC.
  • Telnet: Telnet is not a secure protocol and is unencrypted. Block port 23 to restrict access to it
  • Memorable Numbers: Some malware authors use easy-to-remember numbers such as 234, 6789, 1111, 666, and 8888
  • File Transfer Protocol (FTP): FTP is used to transfer computer files from a server to a client on a computer network. Block port 21 to restrict this data egress point on client computers.
pexels-mateusz-dach-450035

What Ports Need to Be Left Open?

pexels-mateusz-dach-450035

Port requirements are unique to each organization and its networks; which ones are considered important ports will vary widely based on the software/services used and network setup.

 

The specific ports required by business applications will evolve over time as well. Here are some ways to determine which ones you need to keep open.

 

  • Product Documentation: Consult the manuals of any software and hardware used in your organization and see if they require particular TCP/UDP ports to be left open.
  • Netstat & Resource Monitor: Use a netstat command and Windows resource monitor to identify ports that are currently in use by a specific computer.
  • Trial & Error: If you only use internet-connected computers and have no other special needs, try blocking all ports except for port 80 (HTTP) and port 443 (HTTPS). Test all services and applications in your organization to see if there are any connection issues and monitor IT support tickets for any unforeseen issues.
  • Research Ports: If you need to perform special actions such as file transfers over FTP or hosting your own email servers you’ll need to consult this list to see the ports that are required by each of them.

Try BrowseControl for Free

Fully functional. Easy to use. $6 USD user/month

BrowseControl Web Filtering Features

Category Filtering

Block websites based on specific web content categories

URL Filter

Allowed list or Blocked list for specific URLs

Application Blacklisting

Block specific Windows applications from launching

Block Downloads/Uploads

Prevent uploading and downloading based on file type

Port Filter

Close unused and high-risk TCP/UDP ports

Customize Message

Display a customized warning message on blocked websites

Google Safe Search

Search engine filters prevent explicit results in search engines

Time-Based Policies

Schedule internet access and control browsing based on time

Central Web Console

Save time with a central admin console; optionally integrate Active Directory OUs or security groups

Platform Security

Protect your CurrentWare console with 2FA, passwords, privilege management, and more

Offsite Management

Extend onsite security policies to computers running outside the corporate network

SQL Server Supported

Database scaled for enterprise and large business operations using Microsoft SQL Server

Solutions That Work Across Industries

Tailored controls that help you meet industry standards, boost efficiency, and protect sensitive data across remote and in-office teams.

Healthcare

HIPAA-ready controls to protect PHI with USB management and insider-threat visibility.

Government

Cybersecurity and policy enforcement aligned to NIST 800-171 and CMMC.

Legal Services

Keep client data protected, billable hours productive, and software costs in check.

Manufacturing

Productivity monitoring and internet visibility for both the shop floor and back office.

Financial Services

Enforce access policies and protect sensitive financial data with audit-ready trails.

Schools & Libraries

CIPA-compliant web filtering to qualify for E-Rate and keep students safe online.

Small Business Employee Productivity

Track unproductive web browsing and idle time to detect time-wasting

Built to Support Your Compliance Program

Discover how organizations use CurrentWare to improve visibility, strengthen compliance efforts, and manage employee activity more effectively.

  • CMMC

    Endpoint Restriction to Protect CUI & FCI

    Learn More
  • NIST 800-171/53

    Protect Controlled Unclassified Information

    Learn More
  • ISO 27001

    Increase the Maturity of Your ISO27K ISMS

    Learn More
  • HIPAA

    HIPAA protects sensitive patient data

    Learn More
  • Cyber Essentials

    Critical Security Controls For Your Assessment

    Learn More
  • GDPR

    EU’s data protection and privacy law

    Learn More
  • NERC CIP

    Protect TCAs & BCSI From Insider Threats

    Learn More
  • CIPA for Education

    Qualify for the FCC’s E-Rate Program

    Learn More

Pick & Plug Into Your Existing Stack

CurrentWare works alongside the identity, security, and directory tools you already use, including support for SAML, OIDC, and CEF standards. Cloud connectors are on the way.

  • Tested & supported
  • Generic standards (SAML, OIDC, CEF)
  • On the roadmap (Cloud)

  • Splunk Logo
  • Pingone Logo
  • Onelogin Logo
  • Microsoft ADFS Logo
  • IBM Qradar Logo
  • Logrhythm Logo
  • 87798951-6642-4db9-832b-89b48b8add96
  • Microsoft Active Directory Logo
  • Jumpcloud Logo
  • Elastic Logo
  • Microsoft ADFS Logo
  • ManageEngine Logo
  • Microsoft Entra Logo
  • e1f69ad3-8f24-445a-88a5-d269c11dcade

Keep reading

Articles

View All Blogs

Try BrowseControl for Free

Fully functional. Easy to use. $6 USD user/month

Start Free Trial Book a Demo
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy