Port 17500Dropbox LAN Sync

Dropbox LAN Sync utilizes TCP and UDP port 17500 to efficiently synchronize files between Dropbox clients on the same local network, enabling accelerated file sharing without relying solely on internet connectivity..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
43,713

rank 27 of 993 · top 3%

Technical Details

what runs on :17500

Dropbox LAN Sync is a feature integrated into the Dropbox client application that optimizes file synchronization within a local network environment. This mechanism helps reduce external bandwidth consumption by transferring files directly between devices connected to the same network.

The protocol employs UDP port 17500 initially for discovery purposes. When a Dropbox client is active, it sends broadcast packets to the local subnet over UDP. Other Dropbox clients listening on the same port receive these packets and, if associated with the same account, acknowledge their presence. This mutual awareness facilitates the direct exchange of files.

Following the discovery process, Dropbox clients establish TCP sessions over port 17500 to handle the actual file transfers. This direct connection method ensures higher data integrity, reliability, and faster synchronization compared to routing data solely through Dropbox's cloud servers. By offloading local file transfers to the LAN, Dropbox LAN Sync enhances performance and efficiency for collaborative, multi-device Dropbox users.

Security Information

exposure of :17500

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

file transfer averages 4.1 across 114 ports — this one sits 0.1 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

From a security perspective, open exposure of UDP discovery broadcasts on port 17500 may leak information about Dropbox clients present within the network, potentially assisting an attacker in network reconnaissance or lateral movement.

Common vulnerabilities include:

  • Unauthorized access if network segmentation is inadequate
  • Potential data interception during file transfer due to unencrypted communication (when encryption is not enabled)
  • Misconfigured firewalls allowing unwanted inbound/outbound traffic on port 17500

Mitigations typically involve:

  • Restricting UDP broadcasts and TCP connections to trusted segments or hosts
  • Employing firewalls to limit access strictly within organizational boundaries
  • Using strong peer authentication within the Dropbox ecosystem
  • Enabling encryption features when available or utilizing VPN tunnels to secure inter-client communications
  • Network monitoring to identify anomalous Dropbox LAN Sync activity that could indicate misuse or compromise

the 8 most looked-up other ports in file transfer — 114 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted