Port 2152GTP User Plane

Carries encapsulated mobile-network user traffic between radio and core-network nodes.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 994 of 3,890 · top 26%

Technical Details

what runs on :2152

GTP-U encapsulates user IP packets in GPRS Tunnelling Protocol packets identified by a Tunnel Endpoint Identifier (TEID). It normally runs over UDP port 2152; the registry also lists TCP, but standard mobile-network deployments overwhelmingly use UDP. GTP control-plane traffic is commonly associated with UDP/2123, while GTP' charging traffic uses UDP/TCP/3386. GTP-U provides tunnelling and sequencing options, but no native encryption or strong peer authentication.

Security Information

exposure of :2152

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

network services averages 2.7 across 1,273 ports — this one sits 4.3 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

GTP-U should generally be restricted to trusted mobile-core and transport-network interfaces, not exposed to the public internet. Because the protocol has no native confidentiality or robust authentication, an exposed endpoint may permit traffic injection, tunnel abuse, spoofing, subscriber-data disclosure, or denial-of-service; operators commonly rely on private transport, filtering, and sometimes IPsec.

the 8 most looked-up other ports in network services — 1,273 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted