Port 2604Quagga/FRRouting OSPF daemon VTY
TCP/2604 is commonly the Quagga/FRRouting OSPF daemon’s management CLI, not OSPF routing traffic.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 8/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
risk
rank 993 of 4,164 · top 24%
also known as nsc-ccs, Quagga ospfd
Technical Details
what runs on :2604The IANA assignment is nsc-ccs, but a well-established real-world use of TCP/2604 is the Quagga/FRRouting ospfd VTY: a line-oriented management CLI, not the OSPF protocol itself. OSPF routing messages use IP protocol 89, not TCP or UDP. The VTY accepts a TCP connection and provides command-line access according to the daemon’s configured authentication and privilege settings; it is commonly kept on a management interface or bound to localhost. Neighboring Quagga/FRR VTY ports include 2601 for zebra, 2602 for ripd, and 2605 for bgpd. The VTY convention applies to TCP; UDP/2604 is not the normal ospfd management listener.
Security Information
exposure of :2604risk score
8/ 10risk
treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.
remote access averages 3.7 across 190 ports — this one sits 4.3 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
An exposed VTY is a router-management surface: an attacker who can authenticate may inspect or alter routing configuration and affect network traffic. Keep it off the public internet and limit access with management-plane ACLs, a VPN, or an out-of-band network. The CLI is not encrypted by default, so credentials and commands may be exposed to observers on the path.
Related Ports
the 8 most looked-up other ports in remote access — 190 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted