Port 2408Cloudflare Railgun

Cloudflare Railgun's encrypted TCP channel between an origin-side listener and Cloudflare's edge.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
3/10

caution

lookups
0

rank 993 of 4,034 · top 25%

also known as railgun-webaccl

Technical Details

what runs on :2408

Railgun uses TCP port 2408 for a proprietary, encrypted channel between the origin-side Railgun listener and Cloudflare's Railgun service. The listener maintains a session with Cloudflare and exchanges optimized web-resource requests and responses; the public wire format and detailed handshake/framing are proprietary rather than an HTTP protocol exposed directly to clients. It is normally the listener's dedicated service port and is unrelated to the origin's usual HTTP and HTTPS ports, 80 and 443.

Security Information

exposure of :2408

risk score

3/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

web services averages 3.3 across 177 ports — this one sits 0.3 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

The listener should not be broadly reachable from the Internet: restrict TCP/2408 to Cloudflare's published source ranges and use the deployment's authentication and key-management controls. Although the channel is encrypted and intended for authenticated Cloudflare peers, an unnecessarily exposed or outdated listener increases attack surface and can permit unauthorized service interaction or resource consumption.

the 8 most looked-up other ports in web services — 177 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted