Port 13720NetBackup bprd

NetBackup bprd is a key daemon within the Symantec (formerly VERITAS) NetBackup suite, responsible for managing backup, restore, and policy operations. The bprd process listens on TCP and UDP port 13720 to facilitate communication between NetBackup clients, media servers, and administration tools, supporting enterprise-grade data protection and recovery across various environments..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
7,409

rank 686 of 993 · top 69%

Technical Details

what runs on :13720

The NetBackup bprd service acts as the primary request daemon in the Symantec NetBackup architecture, coordinating connections and commands between clients, media servers, and master servers. It processes requests for all backup, restore, catalog, and scheduling operations, making it integral to the overall management of backup workflows.

Operating over TCP and UDP port 13720, bprd is responsible for interpreting commands from NetBackup client agents and administrative consoles. It validates requests, authenticates users, and brokers communication between different components, ensuring data is correctly handled according to defined backup policies, retention schedules, and resource management parameters.

Due to its central role, the bprd daemon requires consistent connectivity and appropriate resource allocation. In complex enterprise environments with high backup volumes, careful performance tuning and monitoring of bprd can be necessary to optimize throughput, reduce bottlenecks, and ensure dependable data protection operations.

Security Information

exposure of :13720

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

system averages 3.9 across 342 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Unauthorized access if network segmentation or authentication is insufficient
  • Exploitation of outdated software that contains known security flaws
  • Potential misuse through open exposure of the port to untrusted networks

Common Mitigations:

  • Restrict port 13720 access using network firewalls and ACLs, permitting only trusted hosts
  • Enforce strong authentication and authorization policies within NetBackup
  • Regularly update NetBackup components to patch security vulnerabilities
  • Segment backup networks from user and public networks to reduce attack surface
  • Where possible, encrypt management traffic to provide confidentiality and integrity protection even though native communication is unencrypted

the 8 most looked-up other ports in system — 342 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted