Port 2598Citrix ICA Session Reliability
TCP port 2598 is used by Citrix Independent Computing Architecture (ICA) protocol when Session Reliability is enabled, providing a seamless user experience during momentary network disruptions. Unlike the standard ICA port 1494, port 2598 supports the Common Gateway Protocol (CGP), allowing Citrix sessions to maintain connectivity without user interruption by buffering data until the network stabilizes..
- transport
- tcp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 10,987
single transport
payload readable on path
used by convention
caution
rank 392 of 993 · top 39%
Technical Details
what runs on :2598TCP port 2598 is primarily associated with Citrix ICA protocol in implementations where Session Reliability is enabled. In such scenarios, Citrix uses the Common Gateway Protocol (CGP) to encapsulate the ICA protocol, enabling connection stability. This port acts as an intermediary that handles disconnections by keeping the session active even if the underlying network is temporarily unavailable.
When a user connects to a Citrix XenApp or XenDesktop environment, the initial handshake may occur over TCP port 2598 if Session Reliability is turned on. CGP intercepts and maintains the ICA session, buffering and managing packets during brief interruptions. This ensures user applications remain responsive, and the session state is preserved throughout the connectivity hiccup.
Compared to the standard port 1494, which provides a direct connection for ICA, port 2598 offers enhanced resiliency. It is important for system administrators to configure firewalls and network appliances to allow traffic on this port to fully utilize Session Reliability features and optimize end-user experience.
Security Information
exposure of :2598risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
remote access averages 4.0 across 110 ports — this one sits level with it.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common vulnerabilities with TCP port 2598 include exposure to unauthorized access if not adequately protected. ICA sessions could be intercepted or hijacked, especially if communication is unencrypted, enabling man-in-the-middle attacks. Attackers might attempt denial-of-service attacks targeting port 2598 to disrupt services or exploit vulnerabilities in Citrix services.
Mitigation strategies involve enforcing strong authentication like multi-factor authentication, restricting access using network segmentation and firewalls, and enabling encryption such as SSL/TLS tunneling of ICA traffic. Regular patching of Citrix infrastructure to address newly discovered vulnerabilities is also critical. Monitoring network activity on this port can help detect suspicious behavior early and prevent potential compromise.
Related Ports
the 8 most looked-up other ports in remote access — 110 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted