Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

La porta 80 è quella predefinita per HTTP, normalmente non cifrato; la porta 443 è quella predefinita per HTTPS, cioè HTTP protetto da TLS. Non sono porte fisiche né garantiscono da sole che un sito funzioni o sia sicuro: indicano un punto di comunicazione su un dispositivo. Per un sito accessibile solo in HTTPS può bastare 443; se il server deve anche reindirizzare le richieste HTTP a HTTPS, in genere serve anche 80.

Porta Uso convenzionale Schema URL Cifratura Trasporto tipico
80 HTTP http:// No, normalmente TCP
443 HTTPS https:// Sì, tramite TLS TCP; UDP per HTTP/3 su QUIC

Questi sono gli usi standard registrati, non vincoli tecnici: un amministratore può configurare HTTP su 8080, HTTPS su 8443 o un servizio diverso su 80 o 443. La registrazione IANA indica le convenzioni, ma non dimostra che un servizio sia effettivamente in ascolto.

Che cos’è una porta di rete?

L’indirizzo IP identifica un dispositivo raggiungibile in rete; il numero di porta individua un punto di comunicazione associato a un servizio. Per esempio, in 203.0.113.10:443, la prima parte è l’indirizzo IP e 443 è la porta di destinazione. Una porta è un endpoint logico, non un connettore fisico. Per approfondire, si veda la definizione di porta di rete.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nei normali URL il browser usa la porta predefinita dello schema e spesso non la mostra: http://esempio.it equivale normalmente a http://esempio.it:80, mentre https://esempio.it equivale a https://esempio.it:443. Una porta diversa va indicata esplicitamente, come in http://localhost:8080. La sintassi è descritta da MDN.

#1 Best Overall
Sale
UGREEN Cat 8 Ethernet Cable 6FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 6FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5

A cosa serve la porta 80?

La porta 80 è quella predefinita per HTTP, il protocollo applicativo con cui browser e server web scambiano richieste e risposte. HTTP senza TLS non cifra la comunicazione: chi riesce a intercettarla lungo il percorso può potenzialmente leggerla o modificarla. Il problema è l’assenza di protezione, non il numero 80 in sé: sulla stessa porta si può configurare tecnicamente un servizio diverso.

La porta 80 può essere mantenuta per ricevere vecchi collegamenti HTTP e rispondere con un reindirizzamento a HTTPS, o per particolari necessità di compatibilità e verifica del dominio. Un redirect è utile, ma non protegge la prima richiesta HTTP: quando possibile, è preferibile usare direttamente l’indirizzo HTTPS.

A cosa serve la porta 443?

La porta 443 è quella predefinita per HTTPS. HTTPS è HTTP trasportato su una connessione protetta da TLS; non è semplicemente una “porta SSL”. SSL è il nome storico di protocolli obsoleti: per HTTPS moderno si parla di TLS. La specifica HTTP definisce lo schema HTTPS e la porta TCP predefinita 443; le proprietà di TLS 1.3 sono descritte nella relativa specifica.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Jadaol Cat6/Cat6A Ethernet Cable 50FT Flat with Clips 10Gbps Network, White
  • Cat 6 performance at a Cat5e price but with higher bandwidth
  • High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
  • Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
  • UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
  • The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.

Con una configurazione corretta, TLS protegge la riservatezza e l’integrità del traffico e consente al browser di verificare il certificato del server per il dominio richiesto. Ma una connessione su 443 non rende automaticamente sicuro tutto il sito: certificato, configurazione TLS, applicazione, autenticazione e gestione delle sessioni contano tutti. Anche un sito di phishing o vulnerabile può avere un certificato valido.

HTTP e HTTPS: cosa cambia davvero?

  • HTTP sulla 80: normalmente traffico non cifrato; può essere utile per un redirect, ma non protegge i dati scambiati.
  • HTTPS sulla 443: HTTP protetto da TLS, se certificato e configurazione sono corretti.
  • Porta omessa nell’URL: il browser usa normalmente la porta predefinita per lo schema, senza che questo significhi che non stia usando una porta.
  • Numero non sufficiente: vedere 80 o 443 non prova quale servizio risponda, né che il sito sia funzionante.

Devo aprire entrambe le porte?

Dipende dal servizio e dalla direzione del traffico. “Aprire una porta” di solito significa consentire connessioni in ingresso attraverso un firewall o configurare il port forwarding sul router. Non è normalmente necessario per navigare dal computer di casa: browser e sistema operativo avviano connessioni in uscita e ricevono le relative risposte.

  • Sito disponibile solo in HTTPS: in genere consentire 443/tcp. Se server e infrastruttura supportano HTTP/3, si può consentire anche 443/udp, ma non è indispensabile per HTTPS.
  • Sito che reindirizza HTTP a HTTPS: normalmente consentire 80/tcp per ricevere la richiesta iniziale e 443/tcp per la navigazione protetta. L’eventuale 443/udp è una scelta separata per HTTP/3.
  • Server dentro una rete domestica, raggiungibile da Internet: oltre alle regole del firewall, il router deve inoltrare la porta pubblica al dispositivo e alla porta locale corrette.

Per un sito ospitato in rete locale, una regola NAT tipica indirizza le richieste dall’IP pubblico del router a un IP privato del server sulla porta del servizio. Verifica che il server abbia un IP privato stabile o una prenotazione DHCP, che la regola di port forwarding e i firewall di router e server siano corretti, che il DNS punti all’IP pubblico giusto e che il certificato TLS corrisponda al dominio. Il CGNAT del provider può impedire connessioni in ingresso IPv4; IPv6 richiede regole firewall appropriate e non usa necessariamente lo stesso percorso NAT.

Rank #3
DbillionDa Cat 8 Ethernet Cable, 6FT 40Gbps 2000MHz RJ45 LAN Cable
  • Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
  • 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
  • F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
  • RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
  • Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.

Perché si parla di TCP e UDP sulla 443?

HTTP/1.1 e HTTP/2 usano normalmente TCP; HTTPS protegge la connessione con TLS. HTTP/3 usa invece QUIC, trasporto basato su UDP che include meccanismi di sicurezza e affidabilità. Perciò, in termini pratici, 443/tcp serve tipicamente HTTPS tradizionale e 443/udp può servire HTTP/3/QUIC se server, proxy, bilanciatori e firewall lo supportano. Lo standard RFC 9114 definisce HTTP/3 sopra QUIC; non ne consegue che ogni server HTTPS debba esporre UDP 443.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Come verificare le porte e il sito

Un test di porta e un test del sito rispondono a domande diverse. Una connessione TCP riuscita indica che si è potuto raggiungere un endpoint TCP; non verifica certificato, contenuto, DNS corretto per tutti gli utenti o funzionamento dell’applicazione. Esegui test di scansione solo su sistemi tuoi o per i quali hai autorizzazione.

Verificare una risposta HTTP o HTTPS

curl -I http://example.com
curl -I https://example.com
curl -I -L http://example.com
curl -vI https://example.com

-I richiede le intestazioni; -L segue i redirect; -v mostra dettagli della connessione, inclusi elementi utili per diagnosticare TLS. Un possibile risultato HTTP è un codice 301 con intestazione Location: https://example.com/. Indica un redirect permanente, non prova da solo che la destinazione HTTPS funzioni. Output e protocolli negoziati variano con curl, sistema, proxy e server. Vedi la documentazione di curl.

Rank #4
Smolink Cat 8 Ethernet Cable, 50ft 40Gbps 2000MHz RJ45 LAN Cable
  • Cat 8 Speed, Cat 5/5e Value Enjoy Cat 8 Ethernet cable performance at a Cat 5/5e-level value. With up to 40Gbps speed and 2000MHz bandwidth, this high speed internet cable delivers more bandwidth than standard Cat 5 and Cat 5e cables, helping support smooth gaming, streaming, video calls, large file transfers and everyday wired network use.
  • 40Gbps Speed, Wide Compatibility This Cat 8 Ethernet cable supports up to 40Gbps data transfer and 2000MHz bandwidth for fast, reliable internet performance. Standard RJ45 connectors are backward compatible with Cat7, Cat6, Cat6a and Cat5e devices, including routers, modems, switches, gaming PCs, PS5, PS4, Xbox, smart TVs, laptops and printers.
  • Stable U/FTP Shielding Each of the 4 twisted pairs is individually wrapped with aluminum foil to help reduce crosstalk, noise, and signal interference. Combined with RJ45 connectors on both ends, the U/FTP design helps maintain cleaner signal transmission for a stable and reliable wired network connection.
  • Nylon Braided Durability The nylon braided jacket adds everyday durability while keeping the cable flexible and easy to route. Reinforced construction helps the cord handle bending, pulling and frequent plugging, making it a reliable choice for desks, gaming rooms, home offices and long-term network setups.
  • 50ft Reach for More Setups The 50 ft length makes it easier to connect devices across rooms, along walls, under desks or around corners. Great for router-to-PC connections, modem-to-TV setups, gaming consoles, workstations, printers and other home network equipment that needs a longer Ethernet cable.

Verificare una connessione TCP da Windows

Test-NetConnection example.com -Port 80
Test-NetConnection example.com -Port 443

Nel risultato, TcpTestSucceeded : True significa che il test TCP è riuscito. Non verifica il certificato né l’applicazione web. La documentazione è disponibile per Test-NetConnection.

Verificare da Linux o macOS

Con Netcat, se installato:

nc -vz example.com 80
nc -vz example.com 443

Con Nmap, se installato:

nmap -p 80,443 example.com

Una scansione può essere bloccata o filtrata e non equivale a una verifica completa del servizio; usala solo con autorizzazione. Consulta il manuale di Nmap.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Controllare i servizi in ascolto sul proprio server

Su Linux:

ss -ltnp
ss -ltnp '( sport = :80 or sport = :443 )'

Su macOS:

lsof -nP -iTCP:80 -sTCP:LISTEN
lsof -nP -iTCP:443 -sTCP:LISTEN

In Windows PowerShell:

Get-NetTCPConnection -State Listen -LocalPort 80,443

Questi comandi controllano l’ascolto locale TCP, non UDP 443 né la raggiungibilità dall’esterno. Se un servizio non compare, può non essere avviato, essere in ascolto su un’altra interfaccia o usare una porta diversa.

Best Value
MORELECS Cat 7 Flat Ethernet Cable 6.6FT,10Gbps,Braided,Shielded(3FT-150FT)
  • [Flat Design, Zero Cable Clutter] - Lies perfectly flat against walls, under rugs, along baseboards, and through tight spaces without kinks, tangles, or messy coils. Customers praise it for effortless installation and clean cable management that blends into any room.
  • [REINFORCED BRAIDED CONSTRUCTION FOR LONG‑LASTING PERFORMANCE] - Premium cotton braided jacket paired with reinforced RJ45 connectors delivers outstanding durability, rigorously tested for over 15,000 bend cycles. Many customers describe this ethernet cable as rock‑solid and well‑crafted, ideal for long‑term daily use with no worries about premature wear‑and‑tear or connection failure
  • [10GBPS SPEED & 600MHZ BANDWIDTH — GAMING, STREAMING & FIBER READY] - Delivers 10Gbps data transfer rate with 600MHz bandwidth for PS5, Xbox, 4K streaming, and fiber internet. Customers report stable performance and fast speeds. Backward compatible with Cat 6 and Cat 5e devices
  • [STP SHIELDING & GOLD-PLATED RJ45 — MINIMIZES EMI/RFI INTERFERENCE] - 100% bare copper STP shielding helps protect signal integrity when routed near power cords. Gold-plated RJ45 connectors resist corrosion. Compatible with 2.5GB network card
  • [Works with Everything — Router, Modem, PS5, Xbox, PC, Smart TV, Printer More ] - Full backward compatibility with Cat7, Cat6, Cat6a, and Cat5e devices means this one cable works with all your home or office equipment today, and future upgrades tomorrow. Works with 10/100/1000/10G/40G BASE-T speeds. Includes 36-month warranty with free replacement support
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Se una porta o il sito non funziona

  1. Controlla il nome e il DNS. Verifica che il dominio punti all’indirizzo previsto. Se il DNS restituisce più indirizzi, o usa un CDN, i test possono raggiungere endpoint diversi.
  2. Verifica il servizio in ascolto. Sul server controlla che il web server o il proxy sia avviato e ascolti sulla porta e sull’interfaccia corrette.
  3. Prova il protocollo giusto. Una porta aperta non garantisce che vi risponda HTTP o TLS. Un servizio non TLS sulla 443 può causare un errore del browser.
  4. Controlla i firewall. Verifica direzione, TCP o UDP, porta, interfaccia e regole locali, cloud e router. Per HTTP/3 controlla UDP 443 separatamente.
  5. Verifica routing e port forwarding. Se il server è in LAN, accertati che il router inoltri al suo IP privato corretto e che non intervenga il CGNAT.
  6. Controlla certificato e nome host. Un certificato scaduto, per un nome diverso o con catena incompleta può bloccare HTTPS anche se TCP 443 è raggiungibile. Anche SNI, virtual host, orologio del client e compatibilità TLS possono contare.
  7. Confronta IPv4 e IPv6. Il sito può funzionare su una famiglia di indirizzi ma non sull’altra, oppure il test può controllare un indirizzo diverso da quello usato dal browser.
  8. Considera proxy, CDN e rete di prova. Un reverse proxy può accettare la 443 ma non raggiungere il server d’origine. NAT loopback può far fallire un test del proprio IP pubblico dall’interno della LAN, mentre il sito funziona dall’esterno.
  9. Prova da una rete esterna. Per un servizio pubblico, testa da una connessione diversa dalla rete che ospita il server: alcune regole permettono accesso solo da specifici indirizzi o proxy.

Se il sito funziona sulla 443 ma non sulla 80, la causa può essere semplicemente una configurazione solo HTTPS o l’assenza del redirect HTTP. Se la 443 è raggiungibile ma il browser mostra un errore, distingui tra problema di certificato/TLS, virtual host o reverse proxy e problema dell’applicazione. Un 404 o 502, per esempio, indica che la connessione ha raggiunto un servizio HTTP, ma non che la pagina richiesta sia disponibile.

Una porta aperta è un rischio di sicurezza?

Non automaticamente. Il rischio dipende dal programma in ascolto, dalla sua versione e configurazione, da ciò che espone, dall’autenticazione e dalla possibilità che sia raggiunto da Internet. HTTP sulla 80 può esporre contenuti non cifrati; HTTPS sulla 443 può essere mal configurato o ospitare un’applicazione vulnerabile. Evita regole troppo ampie: consenti soltanto i protocolli e le porte necessari, limita gli indirizzi di origine quando possibile e mantieni aggiornati i servizi esposti.

Una regola firewall per un web server pubblico potrebbe consentire in ingresso TCP 80 se serve HTTP o redirect, TCP 443 per HTTPS e, facoltativamente, UDP 443 per HTTP/3. Non aprire tutte le porte per risolvere un problema: la regola deve corrispondere al servizio e alla direzione di traffico necessari. Per Windows, Microsoft descrive la gestione delle regole di Windows Defender Firewall.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In breve: porta aperta non significa sito funzionante

  1. Porta raggiungibile: i pacchetti arrivano a un endpoint.
  2. Servizio in ascolto: un processo accetta la connessione.
  3. Protocollo corretto: il servizio parla HTTP o HTTPS come previsto.
  4. Configurazione corretta: DNS, certificato, virtual host, proxy e routing coincidono.
  5. Applicazione funzionante: il server restituisce la pagina o la risposta desiderata.

Un controllo positivo della porta riguarda soprattutto i primi passaggi: non certifica il resto.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.