Port 2598Citrix ICA Session Reliability

TCP port 2598 is used by Citrix Independent Computing Architecture (ICA) protocol when Session Reliability is enabled, providing a seamless user experience during momentary network disruptions. Unlike the standard ICA port 1494, port 2598 supports the Common Gateway Protocol (CGP), allowing Citrix sessions to maintain connectivity without user interruption by buffering data until the network stabilizes..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
10,987

rank 392 of 993 · top 39%

Technical Details

what runs on :2598

TCP port 2598 is primarily associated with Citrix ICA protocol in implementations where Session Reliability is enabled. In such scenarios, Citrix uses the Common Gateway Protocol (CGP) to encapsulate the ICA protocol, enabling connection stability. This port acts as an intermediary that handles disconnections by keeping the session active even if the underlying network is temporarily unavailable.

When a user connects to a Citrix XenApp or XenDesktop environment, the initial handshake may occur over TCP port 2598 if Session Reliability is turned on. CGP intercepts and maintains the ICA session, buffering and managing packets during brief interruptions. This ensures user applications remain responsive, and the session state is preserved throughout the connectivity hiccup.

Compared to the standard port 1494, which provides a direct connection for ICA, port 2598 offers enhanced resiliency. It is important for system administrators to configure firewalls and network appliances to allow traffic on this port to fully utilize Session Reliability features and optimize end-user experience.

Security Information

exposure of :2598

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

remote access averages 4.0 across 110 ports — this one sits level with it.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common vulnerabilities with TCP port 2598 include exposure to unauthorized access if not adequately protected. ICA sessions could be intercepted or hijacked, especially if communication is unencrypted, enabling man-in-the-middle attacks. Attackers might attempt denial-of-service attacks targeting port 2598 to disrupt services or exploit vulnerabilities in Citrix services.

Mitigation strategies involve enforcing strong authentication like multi-factor authentication, restricting access using network segmentation and firewalls, and enabling encryption such as SSL/TLS tunneling of ICA traffic. Regular patching of Citrix infrastructure to address newly discovered vulnerabilities is also critical. Monitoring network activity on this port can help detect suspicious behavior early and prevent potential compromise.

the 8 most looked-up other ports in remote access — 110 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted