Firewall Test

This checks which ports on your internet connection answer from the outside. It runs from our server against the address your connection is using right now, so what you see is roughly what anyone else on the internet would see.

Port scanner

Checks which ports on your connection answer from the outside. Pick any port or range you want.

Testing this address checking reading your connection
Test your own connection only. If you are at work, at school, or on shared wifi, this address belongs to the network rather than to your computer, and the results describe their firewall instead of yours. Do not run this on a network you are not responsible for.

What the results mean

There are four answers, and the difference between them matters more than the count does.

  • Answered. Something accepted the connection. A service is listening on that port and it can be reached from the internet.
  • Refused. Your network replied and turned the connection down. Nothing is listening there, and your own equipment said so.
  • No reply. Nothing came back before we stopped waiting. Usually a firewall dropping the traffic before it reaches anything.
  • Could not test. We never reached your network, so the row tells you nothing either way. We say that plainly instead of counting it as closed, because a port nobody tested is not a port anybody can vouch for.

Refused and no reply are both ordinary, and neither one leaves anything listening. If a result surprises you, why port checks fail goes through the cases that catch people out.

A port answered. Now what?

An answering port is not automatically a problem. It becomes one when you did not mean to open it.

Start with the port forwarding list on your router, because on a home connection that is where nearly every open port comes from. Read down it and check every entry is one you put there. If you do not recognise a rule, look the port up before you touch it, and if it turns out not to be yours, take it out.

If the forwarding list is empty and a port still answers, something on the network opened it without being asked, and that is worth tracking down rather than closing and forgetting about.

Firewalls that stop answering partway through

Some firewall gear watches for port scans and stops replying to the source once it decides it is being scanned. If that happens partway through a run, every port checked afterwards comes back as no reply whatever is really there, and the result reads as an all clear that nobody earned.

The old advice, on this site and plenty of others, was to switch that protection off before testing. We do not give that advice any more. Turning off a working defence to make a test look tidier is a poor trade, and it made no difference when we tried it. We switched scan protection on, restarted a current consumer router, and ran a full 1,024 ports: the results came back exactly as they had with the setting off. Five bursts fired back to back did the same.

So the scanner checks instead of asking you to change anything. At the end of a run it goes back to a few ports that answered early and asks them again. If they have gone quiet, it says so, because that is the pattern a firewall shutting the door would leave behind. If they still answer, your connection was talking to us the whole way through and the result stands on its own.

Testing a network that is not yours

The test always runs against the address your connection presents to the internet, and that address is not always yours. At work, at school, in a hotel or on shared wifi it belongs to the network, so the result describes their firewall rather than your computer. Do not run it there.

If you are responsible for a company network and you want it tested, that is a conversation with whoever runs it rather than a button on a website.

Going further

Terms, privacy, and connections from our scanner

Using this tool means you accept our terms of service, including the rule that you test only connections you are responsible for. Our privacy statement covers what a scan records and how long we keep it.

If you arrived here because you saw a connection from our scanner in a firewall log, this page explains what it was and how to have a range excluded.

© 2002-2026 AuditMyPC.com