Port
In short: A number (0–65535) that is assigned within a device to a particular service or application, so that several network connections can be distinguished at the same time.
In more detail: An IP address identifies the device, the port the specific application on it — e.g. port 80 for HTTP, port 443 for HTTPS, port 22 for SSH. The first 1023 ports are considered “well-known ports” with a standardised assignment (standard port).
In Depth
The port range (0–65535) is divided into three zones: well-known ports (0–1023, reserved by IANA for standard services, e.g. 80 for HTTP, 443 for HTTPS, 22 for SSH, 53 for DNS), registered ports (1024–49151, registered with IANA by software vendors, but not exclusively protected) and dynamic/private/ephemeral ports (49152–65535, free for temporary connections such as clients’ source ports).
A port alone doesn’t uniquely identify a connection — it always has to be seen in the context of an IP address and a transport protocol (TCP or UDP). This combination of IP address + port + protocol is called a socket. Two different applications can certainly use the same port if they speak different protocols (e.g. port 53 for DNS over both TCP and UDP) — operating systems therefore manage TCP and UDP ports completely separately from each other.
Source port and destination port
Every connection actually involves two ports: the destination port (the known, fixed port of the requested service, e.g. 443 for HTTPS) and the source port (a temporary port chosen at random from the ephemeral range by the requesting device’s operating system for exactly this one connection). This asymmetry allows a single device to hold several connections to the same target server and port at the same time (e.g. several open browser tabs on the same website) — each gets its own unique source port and can therefore be distinguished as a separate connection.
Port scans and security
Because open ports represent potential attack surfaces, systematically testing all ports of a target system (“port scan”, e.g. with the tool Nmap) is one of the first steps both in legitimate security audits and in preparing an attack. A port can report three states: “open” (a service is listening and answers), “closed” (the device answers, but no service runs there) or “filtered” (a firewall silently blocks the request without answering at all) — the latter makes it harder for an attacker to tell whether a device exists at all.
See also: Standard port, Source port, Destination port