9. Open Ports and the Ports List
The Ports page mirrors the Software page. The Ports tab shows the open ports your scans discovered; the Ports List tab is your own record of which ports are meant to be open, and which application owns each one. If you have read chapter 8, this will feel familiar — the differences are noted as they come up.
9.1 The Ports tab
Section titled “9.1 The Ports tab”Only genuinely open ports are counted, from the scanner’s port-discovery plugins. The tab has two controls above the grid.
Group by
Section titled “Group by”A dropdown labelled Group by: with three choices, each producing a different set of columns.
`Per host : port` — one row per host and port. The most detailed view.
| Column | What it shows |
|---|---|
| Host IP, Hostname, OS | The machine. |
| Port | The open port number. |
| Protocol | tcp or udp. |
| Service | The service the scanner attributed to the port — www, ssh and so on. |
| Listener | Only with Show listener on: the process actually listening on that port. |
`Aggregate by port` — one row per port. This is the view for “who has 3389 open?”
| Column | What it shows |
|---|---|
| Port, Protocol, Service | The port. |
| Host Count | How many machines expose it. |
| Listeners | With Show listener on: the distinct listening processes across those machines. Placed before the host lists so it is visible without scrolling. |
| Hostnames, Host IPs | Which machines expose it. |
`Aggregate by host` — one row per machine. This is the view for “what is this server exposing?”
| Column | What it shows |
|---|---|
| Hostname, Host IP, OS | The machine. |
| Port Count | How many distinct ports it has open. |
| Ports | The port numbers, in ascending order. |
| Protocols, Services | The distinct protocols and services seen on it. |
| Listeners | With Show listener on: the distinct listening processes on it. |
Show listener
Section titled “Show listener”The Show listener switch adds the listener column to whichever view you are in. Listener information comes from the operating-system enumeration plugins and, like software enumeration, requires a credentialed scan.
Clicking a row opens a details panel headed with the host and port, using the standard panel controls from section 2.5 — the field search, ⌃ and ⌄, Copy and the ⋮ field chooser.
9.2 The Ports List tab
Section titled “9.2 The Ports List tab”Your own list of expected ports. The file controls are the same as the Software List’s: New (suggesting ports-list.json), Load…, a recent-files dropdown, Auto-load on startup and Use Baseline. Section 8.2 describes them; everything there applies here.
A status line beside the buttons tells you what is loaded and what just happened — for example ports-list.json — 42 port(s) (auto-saves), or No list loaded — click New or Load. Appendix B lists every message.
9.3 Reconciling with the scans
Section titled “9.3 Reconciling with the scans”As with software, NESSviewer counts the differences between your list and the scans and offers them for review. Ports are matched on the combination of protocol, port and service.
| Control | What it does |
|---|---|
| Add from Scan | Review ports the scans found that are not on your list. Tooltip: Review and add ports found in the loaded scans that aren’t on the list. |
| Remove from Scan | Review scan-identified list entries the current scans no longer see. Tooltip: Review and mark scan-identified ports removed when they’re no longer in the loaded scans (manual entries are never flagged). |
| Add Row | Adds a blank entry dated today and opens the editor. Tooltip: Add a blank port entry to edit. |
The same amber flags appear when there is something to review: ⚠ {n} scanned port(s) not on the list — Add and ⚠ {n} list port(s) not in the loaded scans — Remove. Clicking either opens the review dialog.
The dialog is titled Add Ports or Remove Ports. Each candidate is listed as 443/tcp with the service — or service · application — on the right. Everything starts ticked; Select All, Select None, the {n} of {total} selected counter and the Apply ({n}) / Cancel buttons work exactly as described in section 8.3.
9.4 The list columns and the editor
Section titled “9.4 The list columns and the editor”| Column | What it holds |
|---|---|
| Application | The application or process that owns the port. This is the column that makes the list useful — a port with no owner is a question, not a record. |
| Protocol | TCP or UDP. |
| Service | The service name. |
| Ports | The port number or numbers for this entry. |
| Comments | Free text — why it is open, who approved it, which ticket. |
| From Scan | Read-only. Ticked when the entry came from a scan. |
| Date Added / Date Removed | When the entry was added, and when it was marked removed. |
Clicking a row opens the editor panel, headed Edit Port Entry, with Application, Protocol, Service, Ports and Comments as editable fields, plus read-only Identified by scan, Date Added and Date Removed. The Application field carries the hint The owning application/process. Leave blank to fill in later.
The same three buttons appear at the bottom: Mark Removed, Restore and Delete from list, behaving exactly as in section 8.4.
9.5 Bulk actions and saving
Section titled “9.5 Bulk actions and saving”Tick several rows and use the toolbar’s Update or Remove.
`Update` opens a dialog titled Update Ports with the subtitle {n} selected, offering Application, Protocol (a dropdown of TCP and UDP), Service, Ports and Comments. Only the fields you set are written. The status then reads Updated {n} item(s).
`Remove` permanently deletes the selected rows, after the same confirmation dialog described in section 8.5.
Saving works exactly as it does for the software list: there is no Save button, and every change writes itself to your file — or to the baseline — shortly after you stop editing.