Port 1720H.323 Signaling
TCP port 1720 is primarily used for H.323 call signaling, a protocol suite widely employed for real-time voice, video, and data conferencing over IP networks. It manages the setup, control, and termination of interactive communication sessions, enabling interoperability across diverse VoIP and multimedia conferencing equipment. This port facilitates the initial connection negotiation between endpoints before media streams are established..
- transport
- tcp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 26,524
single transport
payload readable on path
registered with iana
caution
rank 60 of 993 · top 6%
Technical Details
what runs on :1720-
Overview: Port 1720 is designated for H.323 call signaling, part of the ITU-T H.323 suite which defines standards for audio, video, and data communications over packet-switched networks like LANs, WANs, and the internet. H.323 provides protocols for session setup, control, media transport, and supplementary services.
-
Call Setup Process: H.323 uses port 1720 to initiate TCP-based signaling via the H.225 protocol for call setup and teardown. The endpoint sends a Q.931 signaling message over TCP/1720 to the remote device or gatekeeper, negotiating session parameters and capabilities. Once established, additional control protocols such as H.245 are used (which may be reassigned to dynamic ports) to negotiate media channel properties.
-
Infrastructure Components: Key H.323 elements include Terminals (endpoints), Gatekeepers (for control and address resolution), Gateways (interworking with other networks), and Multipoint Control Units (MCUs) for conferences. Communication starts over port 1720, with media streams typically using dynamically negotiated UDP ports for RTP.
Security Information
exposure of :1720risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
-
Common Vulnerabilities:
- Unauthorized Access: Weak authentication on H.323 devices or endpoints may allow attackers to impersonate users or intercept sessions.
- DoS Attacks: Flooding port 1720 can disrupt call setup and cause denial of service.
- Eavesdropping: Since signaling and media streams may be transmitted unencrypted, attackers can intercept sensitive audio/video content or call metadata.
- Protocol Exploits: Vulnerabilities within the protocol or device firmware can be exploited to crash systems or gain control.
-
Mitigations:
- Access Controls: Restrict port 1720 access via firewalls and ACLs to trusted IP ranges only.
- Encryption: Use secure variants such as H.235 or deploy network-level encryption (e.g., VPNs) to protect signaling and media content.
- Authentication: Implement strong endpoint authentication and authorization policies.
- Monitoring: Continuously monitor for abnormal traffic patterns or connection attempts.
- Patch Management: Regularly update software and firmware to address known vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted